Commit 81dbb9

2025-12-01 10:02:44 novaflash: -/-
Security Announcements/CVE-2025-13086.md ..
@@ 2,13 2,9 @@
Fix memcmp check for the hmac verification in the 3way handshake being inverted
- This is a stupid mistake but causes all hmac cookies to be accepted,
- thus breaking source IP address validation. As a consequence, TLS
- sessions can be openend and state can be consumed in the server from
- IP addresses that did not initiate an initial connection.
+ Due to a program code mistake all hmac cookies are accepted, thus breaking source IP address validation. As a consequence, TLS sessions can be opened and state can be consumed in the server from IP addresses that did not initiate an initial connection.
- While at it, fix check to only allow [t-2;t] timeslots, disallowing
- HMACs coming in from a future timeslot.
+ While at it, fix check to only allow [t-2;t] timeslots, disallowing HMACs coming in from a future timeslot.
OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 are affected. This is fixed in version 2.6.16 and 2.7_rc2.
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9