CVE-2025-2704 - OpenVPN 2.6.1 through 2.6.13 DoS with dynamic tls-crypt-v2
When a P_CONTROL_WKC_V1 is received, OpenVPN sets up tls-crypt-v2 keys. Due to a small oversight, we try to setup tls-crypt-v2 again if receive another P_CONTROL_WKC_V1. Typically this is not harmful if the P_CONTROL_WKC_V1 is actually valid.
But in environments where the duplicated and mangled packets, the key setup via P_CONTROL_WKC_V1 ends up in an unexpected state resulting the OpenVPN server process to assert() and stops running. In practice resulting in a remote DoS attack vector.
CVE record: CVE-2025-2704
OSS Security List: https://www.openwall.com/lists/oss-security/2025/04/02/5
Release note: «OpenVPN 2.6.14 released»
