Commit c338ea

2025-10-23 10:36:54 David Sommerseth: slight styling
Security Announcements/CVE-2025-2704.md ..
@@ 1,7 1,7 @@
# CVE-2025-2704 - OpenVPN 2.6.1 through 2.6.13 DoS with dynamic tls-crypt-v2
- When a P_CONTROL_WKC_V1 is received, OpenVPN sets up tls-crypt-v2 keys. Due to a small oversight, we try to setup tls-crypt-v2 again if receive another P_CONTROL_WKC_V1. Typically this is not harmful if the P_CONTROL_WKC_V1 is actually valid.
+ When a `P_CONTROL_WKC_V1` is received, OpenVPN sets up tls-crypt-v2 keys. Due to a small oversight, we try to setup tls-crypt-v2 again if receive another `P_CONTROL_WKC_V1`. Typically this is not harmful if the `P_CONTROL_WKC_V1` is actually valid.
- But in environments where the duplicated and mangled packets, the key setup via P_CONTROL_WKC_V1 ends up in an unexpected state resulting the OpenVPN server process to assert() and stops running. In practice resulting in a remote DoS attack vector.
+ But in environments where the duplicated and mangled packets, the key setup via `P_CONTROL_WKC_V1` ends up in an unexpected state resulting the OpenVPN server process to `assert()` and stops running. In practice resulting in a remote DoS attack vector.
CVE record: [CVE-2025-2704](https://www.cve.org/CVERecord?id=CVE-2025-2704)
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9