Vulnerability Description
The configuration initialization tool in OpenVPN 3 Linux v20 through v24 on Linux allows a local attacker to use symlinks pointing at an arbitrary directory which will change the ownership and permissions of that destination directory.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openvpn | Openvpn3Linux | >= 20, <= 24 |
| Linux | Linux Kernel | - |
Related Weaknesses (CWE)
References
- https://community.openvpn.net/Security%20Announcements/CVE-2025-3908Vendor Advisory
- http://www.openwall.com/lists/oss-security/2025/05/20/2Mailing List
FAQ
What is CVE-2025-3908?
CVE-2025-3908 is a vulnerability with a CVSS score of 6.2 (MEDIUM). The configuration initialization tool in OpenVPN 3 Linux v20 through v24 on Linux allows a local attacker to use symlinks pointing at an arbitrary directory which will change the ownership and permiss...
How severe is CVE-2025-3908?
CVE-2025-3908 has been rated MEDIUM with a CVSS base score of 6.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-3908?
Check the references section above for vendor advisories and patch information. Affected products include: Openvpn Openvpn3Linux, Linux Linux Kernel.