CVE-2025-13086 - HMAC verification check: fix incorrect memcmp() call
Fix memcmp check for the hmac verification in the 3way handshake being inverted
This is a stupid mistake but causes all hmac cookies to be accepted, thus breaking source IP address validation. As a consequence, TLS sessions can be openend and state can be consumed in the server from IP addresses that did not initiate an initial connection.
While at it, fix check to only allow [t-2;t] timeslots, disallowing HMACs coming in from a future timeslot.
OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 are affected. This is fixed in version 2.6.16 and 2.7_rc2.
CVE Record: CVE-2025-13086
Github: OpenVPN/openvpn-private-issues#56
Release notes: openvpn-2.7_rc2 openvpn-2.6.16
Reported by: Joshua Rogers contact@joshua.hu
Found by: ZeroPath (https://zeropath.com/)
Reported by: stefan@srlabs.de
