CVE-2025-3908

Publication date 19 May 2025

Last updated 26 August 2025


Ubuntu priority

Cvss 3 Severity Score

6.2 · Medium

Score breakdown

Description

The configuration initialization tool in OpenVPN 3 Linux v20 through v24 on Linux allows a local attacker to use symlinks pointing at an arbitrary directory which will change the ownership and permissions of that destination directory.

Status

Package Ubuntu Release Status
openvpn3-client 26.04 LTS resolute
Needs evaluation
25.10 questing
Needs evaluation
25.04 plucky Ignored end of life, was needs-triage
24.10 oracular Not in release
24.04 LTS noble Not in release
22.04 LTS jammy Not in release
20.04 LTS focal Not in release

Severity score breakdown

CVSS version: CVSS v3.0

Base score 6.2 · Medium

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N


Access our resources on patching vulnerabilities