CVE-2024-28882: OpenVPN in a server role accepts multiple exit notifications from authenticated clients which will extend the validity of a closing session
OpenVPN should only call schedule_exit() once for a given peer.
Security scope: An authenticated client can make the server "keep the session" even when the server has been told to disconnect this client.
Affected versions: 2.6.0 until 2.6.10 (inclusive)
References
- Release notes: OpenVPN Mailing List
- CVE record: CVE-2024-28882
- Reported by: Reynir Björnsson
