Blame

c4f02d Samuli Seppänen 2025-01-29 08:37:37 1
# CVE-2024-28882: OpenVPN in a server role accepts multiple exit notifications from authenticated clients which will extend the validity of a closing session
2
df5e1e Samuli Seppänen 2025-02-27 10:17:24 3
only call schedule_exit() once (on a given peer).
c4f02d Samuli Seppänen 2025-01-29 08:37:37 4
df5e1e Samuli Seppänen 2025-02-27 10:17:24 5
Security scope: an authenticated client can make the server "keep the session" even when the server has been told to disconnect this client.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 6
df5e1e Samuli Seppänen 2025-02-27 10:17:24 7
Affected versions: 2.6.0 until 2.6.10 (inclusive)
c4f02d Samuli Seppänen 2025-01-29 08:37:37 8
df5e1e Samuli Seppänen 2025-02-27 10:17:24 9
### References
10
* Release notes: https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07634.html
597b2a novaflash 2025-07-02 16:30:18 11
* CVE record: https://www.cve.org/CVERecord?id=CVE-2024-28882
df5e1e Samuli Seppänen 2025-02-27 10:17:24 12
* Reported by: Reynir Björnsson