Blame
| 7eb29e | uddr | 2026-01-15 20:16:53 | 1 | # CVE-2025-15497 - in epoch key handling (an authenticated remote system can send a valid OpenVPN data packet that triggers an endge case where a too-strict check would trigger an ASSERT(), exiting OpenVPN) |
| 2 | ||||
| 3 | Correctly handle sender jumping exactly epoch_data_keys_future_count |
|||
| 4 | ||||
| 5 | When the sender jumps forwards exactly epoch_data_keys_future_count in its |
|||
| 6 | epoch key use the housekeeping logic does not handle this correctly and |
|||
| 7 | triggers an ASSERT. |
|||
| 8 | ||||
| 9 | Change the code to correctly implement the special case when the new epoch |
|||
| 10 | key of the sender is the highest valid key epoch in the current window of |
|||
| 11 | valid epoch keys for receiving data. |
|||
| 12 | ||||
| 13 | OpenVPN version 2.7_alpha1 through 2.7_rc4 are affected. This is fixed in version 2.7_rc5. |
|||
| 14 | ||||
| 15 | CVE Record: [CVE-2025-15497](https://www.cve.org/CVERecord?id=CVE-2025-15497) |
|||
| 16 | ||||
| 17 | Github: [OpenVPN/openvpn-private-issues#103](https://github.com/OpenVPN/openvpn-private-issues/issues/103) |
|||
| 18 | ||||
| 19 | Release notes: [openvpn-2.7_rc5](https://community.openvpn.net/ReleaseHistory#openvpn-27_rc5-released-15-january-2026) |
|||
| 20 | ||||
| 21 | Reported by: Pavel Kohout of Aisle Research <pavel.kohout@aisle.com> |
