Blame

f8bf7a David Sommerseth 2025-10-23 10:35:41 1
# CVE-2025-2704 - OpenVPN 2.6.1 through 2.6.13 DoS with dynamic tls-crypt-v2
2
c338ea David Sommerseth 2025-10-23 10:36:54 3
When a `P_CONTROL_WKC_V1` is received, OpenVPN sets up tls-crypt-v2 keys. Due to a small oversight, we try to setup tls-crypt-v2 again if receive another `P_CONTROL_WKC_V1`. Typically this is not harmful if the `P_CONTROL_WKC_V1` is actually valid.
f8bf7a David Sommerseth 2025-10-23 10:35:41 4
c338ea David Sommerseth 2025-10-23 10:36:54 5
But in environments where the duplicated and mangled packets, the key setup via `P_CONTROL_WKC_V1` ends up in an unexpected state resulting the OpenVPN server process to `assert()` and stops running. In practice resulting in a remote DoS attack vector.
f8bf7a David Sommerseth 2025-10-23 10:35:41 6
7
CVE record: [CVE-2025-2704](https://www.cve.org/CVERecord?id=CVE-2025-2704)
3f3da4 David Sommerseth 2025-10-23 10:38:28 8
88cd13 David Sommerseth 2025-10-23 10:41:03 9
OSS Security List: [https://www.openwall.com/lists/oss-security/2025/04/02/5](https://www.openwall.com/lists/oss-security/2025/04/02/5)
10
3f3da4 David Sommerseth 2025-10-23 10:38:28 11
Release note: [«OpenVPN 2.6.14 released»](https://www.mail-archive.com/openvpn-announce@lists.sourceforge.net/msg00142.html)