For info, this issue can only be exploited by an authenticated user. So if the only one with an authorized certificate/username is you, then the only person who can crash the OpenVPN server would be yourself.
Therefore nothing to worry about there. The issue is more critical for tunnel providers (as their customers could potentially crash the OpenVPN server), or businesses with malicious/disgruntled employes.
2.3.6 will be included in 376_49 (the code has already been merged on Github for forkers out there).
Finally, while they label this as a security issue, this is more a crashing bug. This can't be used to gain access to a server, or steal any information.