# CVE-2025-12106 - IPv6 address parsing: fix buffer overread on invalid input

socket: reject mismatched address family in get_addr_generic
    
Add a family check to prevent copying address data of the wrong type,
which could cause buffer over-read when parsing routes or endpoints.

OpenVPN version 2.7_alpha1 through 2.7_rc1 are affected. This is fixed in version 2.7_rc2.

CVE Record: [CVE-2025-12106](https://www.cve.org/CVERecord?id=CVE-2025-12106)

Github: [OpenVPN/openvpn-private-issues#77](https://github.com/OpenVPN/openvpn-private-issues/issues/77)

Release notes: [openvpn-2.7_rc2](https://community.openvpn.net/ReleaseHistory#openvpn-27_rc2-released-17-november-2025)

Reported by: Mikhail Khachaiants <mkhachaiants@gmail.com>
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9