Blame
| 839fdf | uddr | 2025-11-18 08:36:49 | 1 | # CVE-2025-12106 - IPv6 address parsing: fix buffer overread on invalid input |
| ae9e49 | David Sommerseth | 2025-10-23 09:22:04 | 2 | |
| 839fdf | uddr | 2025-11-18 08:36:49 | 3 | socket: reject mismatched address family in get_addr_generic |
| 4 | ||||
| 5 | Add a family check to prevent copying address data of the wrong type, |
|||
| 6 | which could cause buffer over-read when parsing routes or endpoints. |
|||
| 7 | ||||
| 8 | OpenVPN version 2.7_alpha1 through 2.7_rc1 are affected. This is fixed in version 2.7_rc2. |
|||
| 9 | ||||
| 10 | CVE Record: [CVE-2025-12106](https://www.cve.org/CVERecord?id=CVE-2025-12106) |
|||
| 11 | ||||
| c13155 | uddr | 2025-11-18 08:40:15 | 12 | Github: [OpenVPN/openvpn-private-issues#77](https://github.com/OpenVPN/openvpn-private-issues/issues/77) |
| 4c85dd | uddr | 2025-11-18 08:40:39 | 13 | |
| 839fdf | uddr | 2025-11-18 08:36:49 | 14 | Release notes: [openvpn-2.7_rc2](https://community.openvpn.net/ReleaseHistory#openvpn-27_rc2-released-17-november-2025) |
| 15 | ||||
| 16 | Reported by: Mikhail Khachaiants <mkhachaiants@gmail.com> |
