Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 953118 (CVE-2025-2704) - net-vpn/openvpn: Possible DoS (CVE-2025-2704)
Summary: net-vpn/openvpn: Possible DoS (CVE-2025-2704)
Status: IN_PROGRESS
Alias: CVE-2025-2704
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL:
Whiteboard: B3 [ebuild]
Keywords: PullRequest
Depends on:
Blocks:
 
Reported: 2025-04-04 12:04 UTC by Agostino Sarubbo
Modified: 2025-04-17 00:00 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2025-04-04 12:04:48 UTC
From https://www.openwall.com/lists/oss-security/2025/04/02/5

The OpenVPN community has released OpenVPN 2.6.14 which includes a
critical security fix.

This issue is fixed in OpenVPN 2.6.14 which has been released today.

-----------------------------------------------------------------
CVE-2025-2704: Fix possible ASSERT() on OpenVPN servers
               using --tls-crypt-v2

OpenVPN servers between 2.6.1 and 2.6.13 using --tls-crypt-v2 can be
made to abort with an ASSERT() message by sending a particular
combination of authenticated and malformed packets.

To trigger the bug, a valid tls-crypt-v2 client key is needed, or
network observation of a handshake with a valid tls-crypt-v2 client key.

No crypto integrity is violated, no data is leaked, and no remote code
execution is possible.  This bug does not affect OpenVPN clients.

(Bug found by internal QA at OpenVPN Inc)
-----------------------------------------------------------------

<https://community.openvpn.net/openvpn/wiki/Downloads#OpenVPN2.6.14--Released02April2025>
<https://community.openvpn.net/openvpn/wiki/CVE-2025-2704>
<https://www.cve.org/CVERecord?id=CVE-2025-2704>
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2025-04-17 00:00:16 UTC
The title isn't right, as 2.6.14 isn't in-tree.