CVE-2024-28882: OpenVPN in a server role accepts multiple exit notifications from authenticated clients which will extend the validity of a closing session

OpenVPN should only call schedule_exit() once for a given peer.

Security scope: An authenticated client can make the server "keep the session" even when the server has been told to disconnect this client.

Affected versions: 2.6.0 until 2.6.10 (inclusive)

References