Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2024-3661

Published: 6 May 2024

DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.

Notes

AuthorNote
rodrigo-zaiden
other VPN softwares may be affected.
as of 2024-05-08, there isn't vpn providers reports
mdeslaur
This issue is actually in the way DHCP clients handle the route
option. There is no clear solution to this issue as of
2024-05-14, marking all packages are deferred for now.

Priority

Medium

Status

Package Release Status
connman
Launchpad, Ubuntu, Debian
bionic Deferred

focal Deferred

jammy Deferred

mantic Deferred

noble Deferred

upstream Needs triage

xenial Deferred

gadmin-openvpn-client
Launchpad, Ubuntu, Debian
bionic Deferred

focal Deferred

jammy Does not exist

mantic Does not exist

noble Does not exist

upstream Needs triage

xenial Deferred

gadmin-openvpn-server
Launchpad, Ubuntu, Debian
bionic Deferred

focal Deferred

jammy Does not exist

mantic Does not exist

noble Does not exist

upstream Needs triage

xenial Deferred

golang-github-apparentlymart-go-openvpn-mgmt
Launchpad, Ubuntu, Debian
focal Deferred

jammy Deferred

mantic Deferred

noble Deferred

upstream Needs triage

kvpnc
Launchpad, Ubuntu, Debian
bionic Deferred

focal Does not exist

jammy Does not exist

mantic Does not exist

noble Does not exist

upstream Needs triage

xenial Deferred

libreswan
Launchpad, Ubuntu, Debian
bionic Deferred

focal Deferred

jammy Deferred

mantic Deferred

noble Deferred

upstream Needs triage

mozillavpn
Launchpad, Ubuntu, Debian
focal Does not exist

jammy Deferred

mantic Does not exist

noble Does not exist

upstream Needs triage

n2n
Launchpad, Ubuntu, Debian
bionic Deferred

focal Deferred

jammy Deferred

mantic Deferred

noble Deferred

upstream Needs triage

xenial Deferred

network-manager-fortisslvpn
Launchpad, Ubuntu, Debian
bionic Deferred

focal Deferred

jammy Deferred

mantic Deferred

noble Deferred

upstream Needs triage

network-manager-iodine
Launchpad, Ubuntu, Debian
bionic Deferred

focal Deferred

jammy Deferred

mantic Deferred

noble Deferred

upstream Needs triage

xenial Deferred

network-manager-l2tp
Launchpad, Ubuntu, Debian
bionic Deferred

focal Deferred

jammy Deferred

mantic Deferred

noble Deferred

upstream Needs triage

network-manager-openconnect
Launchpad, Ubuntu, Debian
bionic Deferred

focal Deferred

jammy Deferred

mantic Deferred

noble Deferred

upstream Needs triage

xenial Deferred

network-manager-openvpn
Launchpad, Ubuntu, Debian
bionic Deferred

focal Deferred

jammy Deferred

mantic Deferred

noble Deferred

upstream Needs triage

xenial Deferred

network-manager-pptp
Launchpad, Ubuntu, Debian
bionic Deferred

focal Deferred

jammy Deferred

mantic Deferred

noble Deferred

upstream Needs triage

xenial Deferred

network-manager-sstp
Launchpad, Ubuntu, Debian
focal Does not exist

jammy Deferred

mantic Deferred

noble Deferred

upstream Does not exist

network-manager-strongswan
Launchpad, Ubuntu, Debian
bionic Deferred

focal Deferred

jammy Deferred

mantic Deferred

noble Deferred

upstream Needs triage

xenial Deferred

network-manager-vpnc
Launchpad, Ubuntu, Debian
bionic Deferred

focal Deferred

jammy Deferred

mantic Deferred

noble Deferred

upstream Needs triage

xenial Deferred

openconnect
Launchpad, Ubuntu, Debian
bionic Deferred

focal Deferred

jammy Deferred

mantic Deferred

noble Deferred

upstream Needs triage

xenial Deferred

openfortivpn
Launchpad, Ubuntu, Debian
bionic Deferred

focal Deferred

jammy Deferred

mantic Deferred

noble Deferred

upstream Needs triage

openvpn
Launchpad, Ubuntu, Debian
bionic Deferred

focal Deferred

jammy Deferred

mantic Deferred

noble Deferred

trusty Deferred

upstream Needs triage

xenial Deferred

pptp-linux
Launchpad, Ubuntu, Debian
bionic Deferred

focal Deferred

jammy Deferred

mantic Deferred

noble Deferred

upstream Needs triage

xenial Deferred

pptpd
Launchpad, Ubuntu, Debian
bionic Deferred

focal Deferred

jammy Deferred

mantic Deferred

noble Does not exist

trusty Deferred

upstream Needs triage

xenial Deferred

quicktun
Launchpad, Ubuntu, Debian
bionic Deferred

focal Deferred

jammy Deferred

mantic Deferred

noble Deferred

upstream Needs triage

riseup-vpn
Launchpad, Ubuntu, Debian
focal Does not exist

jammy Does not exist

mantic Deferred

noble Deferred

upstream Needs triage

softether-vpn
Launchpad, Ubuntu, Debian
focal Does not exist

jammy Deferred

mantic Deferred

noble Deferred

upstream Needs triage

sshuttle
Launchpad, Ubuntu, Debian
bionic Deferred

focal Deferred

jammy Deferred

mantic Deferred

noble Deferred

upstream Needs triage

xenial Deferred

tinc
Launchpad, Ubuntu, Debian
bionic Deferred

focal Deferred

jammy Deferred

mantic Deferred

noble Deferred

upstream Needs triage

xenial Deferred

vpnc
Launchpad, Ubuntu, Debian
bionic Deferred

focal Deferred

jammy Deferred

mantic Deferred

noble Deferred

upstream Needs triage

xenial Deferred

wireguard
Launchpad, Ubuntu, Debian
bionic Deferred

focal Deferred

jammy Deferred

mantic Deferred

noble Deferred

upstream Needs triage

xenial Deferred