This update for openvpn fixes the following issues:
CVE-2026-63650: OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified
by ignoring the configured X.509 username identity lookup field (bsc#1275310).
CVE-2026-84732: Remote Denial of Service via crafted ACK packets (bsc#1279613).