Blame

c4f02d Samuli Seppänen 2025-01-29 08:37:37 1
# CVE-2024-27459: Windows: fix a possible stack overflow in the interactive service component which might lead to a local privilege escalation
2
966a34 Samuli Seppänen 2025-02-27 10:16:07 3
interactive.c: Fix potential stack overflow issue
c4f02d Samuli Seppänen 2025-01-29 08:37:37 4
966a34 Samuli Seppänen 2025-02-27 10:16:07 5
When reading message from the pipe, we first peek the pipe to get the size of the message waiting to be read and then read the message. A compromised OpenVPN process could send an excessively large message, which would result in a stack-allocated message buffer overflow.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 6
7
To address this, we terminate the misbehaving process if the peeked message size exceeds the maximum allowable size.
8
966a34 Samuli Seppänen 2025-02-27 10:16:07 9
### References
10
* Release notes: https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07534.html
bc9e4a novaflash 2025-07-02 16:29:49 11
* CVE record: https://www.cve.org/CVERecord?id=CVE-2024-27459
966a34 Samuli Seppänen 2025-02-27 10:16:07 12
* Reported by: Vladimir Tokarev <​vtokarev@microsoft.com>