Back

HIGH

VTun-ng's failure to initialize encryption modules may cause reversion to plaintext

Published Aug 5, 2025

Description

VTun-ng is a Virtual Tunnel over TCP/IP network. In versions 3.0.17 and below, failure to initialize encryption modules might cause reversion to plaintext due to insufficient error handling. The bug was first introduced in VTun-ng version 3.0.12. This is fixed in version 3.0.18. To workaround this issue, avoid blowfish-256.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Aug 5, 2025
Updated Aug 5, 2025
Reserved Jul 31, 2025

CISA Vulnrichment

Updated Aug 5, 2025

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_M
Published Aug 5, 2025
Updated Aug 5, 2025

GitHub

No data