# CVE-2025-15497 - in epoch key handling (an authenticated remote system can send a valid OpenVPN data packet that triggers an endge case where a too-strict check would trigger an ASSERT(), exiting OpenVPN)

Correctly handle sender jumping exactly epoch_data_keys_future_count
    
When the sender jumps forwards exactly epoch_data_keys_future_count in its
epoch key use the housekeeping logic does not handle this correctly and
triggers an ASSERT.
    
Change the code to correctly implement the special case when the new epoch
key of the sender is the highest valid key epoch in the current window of
valid epoch keys for receiving data.

OpenVPN version 2.7_alpha1 through 2.7_rc4 are affected. This is fixed in version 2.7_rc5.

CVE Record: [CVE-2025-15497](https://www.cve.org/CVERecord?id=CVE-2025-15497)

Github: [OpenVPN/openvpn-private-issues#103](https://github.com/OpenVPN/openvpn-private-issues/issues/103)

Release notes: [openvpn-2.7_rc5](https://community.openvpn.net/ReleaseHistory#openvpn-27_rc5-released-15-january-2026)

Reported by: Pavel Kohout of Aisle Research <pavel.kohout@aisle.com>
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9