Commit 52fa86

2025-11-18 08:46:39 uddr: CVE-2025-13086
Security Announcements/CVE-2025-13086.md ..
@@ 1,3 1,25 @@
- # CVE-2025-13086
+ # CVE-2025-13086 - HMAC verification check: fix incorrect memcmp() call
- [TBD]
+ Fix memcmp check for the hmac verification in the 3way handshake being inverted
+
+ This is a stupid mistake but causes all hmac cookies to be accepted,
+ thus breaking source IP address validation. As a consequence, TLS
+ sessions can be openend and state can be consumed in the server from
+ IP addresses that did not initiate an initial connection.
+
+ While at it, fix check to only allow [t-2;t] timeslots, disallowing
+ HMACs coming in from a future timeslot.
+
+ OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 are affected. This is fixed in version 2.6.16 and 2.7_rc2.
+
+ CVE Record: [CVE-2025-13086](https://www.cve.org/CVERecord?id=CVE-2025-13086)
+
+ Github: [OpenVPN/openvpn-private-issues#56](https://github.com/OpenVPN/openvpn-private-issues/issues/56)
+
+ Release notes: [openvpn-2.7_rc2](https://community.openvpn.net/ReleaseHistory#openvpn-27_rc2-released-17-november-2025) [openvpn-2.6.16](https://community.openvpn.net/ReleaseHistory#openvpn-2616-released-17-november-2025)
+
+ Reported by: Joshua Rogers <contact@joshua.hu>
+
+ Found by: ZeroPath (https://zeropath.com/)
+
+ Reported by: stefan@srlabs.de
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9