CVE-2025-15497 - in epoch key handling (an authenticated remote system can send a valid OpenVPN data packet that triggers an endge case where a too-strict check would trigger an ASSERT(), exiting OpenVPN)
Correctly handle sender jumping exactly epoch_data_keys_future_count
When the sender jumps forwards exactly epoch_data_keys_future_count in its epoch key use the housekeeping logic does not handle this correctly and triggers an ASSERT.
Change the code to correctly implement the special case when the new epoch key of the sender is the highest valid key epoch in the current window of valid epoch keys for receiving data.
OpenVPN version 2.7_alpha1 through 2.7_rc4 are affected. This is fixed in version 2.7_rc5.
CVE Record: CVE-2025-15497
Github: OpenVPN/openvpn-private-issues#103
Release notes: openvpn-2.7_rc5
Reported by: Pavel Kohout of Aisle Research pavel.kohout@aisle.com
