Blame
| 52fa86 | uddr | 2025-11-18 08:46:39 | 1 | # CVE-2025-13086 - HMAC verification check: fix incorrect memcmp() call |
| 522ff4 | David Sommerseth | 2025-11-12 19:50:15 | 2 | |
| 52fa86 | uddr | 2025-11-18 08:46:39 | 3 | Fix memcmp check for the hmac verification in the 3way handshake being inverted |
| 4 | ||||
| 81dbb9 | novaflash | 2025-12-01 10:02:44 | 5 | Due to a program code mistake all hmac cookies are accepted, thus breaking source IP address validation. As a consequence, TLS sessions can be opened and state can be consumed in the server from IP addresses that did not initiate an initial connection. |
| 52fa86 | uddr | 2025-11-18 08:46:39 | 6 | |
| 81dbb9 | novaflash | 2025-12-01 10:02:44 | 7 | While at it, fix check to only allow [t-2;t] timeslots, disallowing HMACs coming in from a future timeslot. |
| 52fa86 | uddr | 2025-11-18 08:46:39 | 8 | |
| 9 | OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 are affected. This is fixed in version 2.6.16 and 2.7_rc2. |
|||
| 10 | ||||
| 11 | CVE Record: [CVE-2025-13086](https://www.cve.org/CVERecord?id=CVE-2025-13086) |
|||
| 12 | ||||
| 13 | Github: [OpenVPN/openvpn-private-issues#56](https://github.com/OpenVPN/openvpn-private-issues/issues/56) |
|||
| 14 | ||||
| 15 | Release notes: [openvpn-2.7_rc2](https://community.openvpn.net/ReleaseHistory#openvpn-27_rc2-released-17-november-2025) [openvpn-2.6.16](https://community.openvpn.net/ReleaseHistory#openvpn-2616-released-17-november-2025) |
|||
| 16 | ||||
| 17 | Reported by: Joshua Rogers <contact@joshua.hu> |
|||
| 18 | ||||
| 19 | Found by: ZeroPath (https://zeropath.com/) |
|||
| 20 | ||||
| 21 | Reported by: stefan@srlabs.de |
