CVE-2024-27459: Windows: fix a possible stack overflow in the interactive service component which might lead to a local privilege escalation
File: interactive.c
Issue: Fix potential stack overflow issue
When reading a message from the pipe, we first peek at the pipe to get the size of the message waiting to be read and then read the message. A compromised OpenVPN process could send an excessively large message, which would result in a stack-allocated message buffer overflow.
To address this, we terminate the misbehaving process if the peeked message size exceeds the maximum allowable size.
References
- Release notes: OpenVPN Users Mailing List
- CVE record: CVE-2024-27459
- Reported by: Vladimir Tokarev vtokarev@microsoft.com
