Bugzilla – Bug 1227546
VUL-0: CVE-2024-28882: openvpn: multiple exit notifications from authenticated clients will extend the validity of a closing session
Last modified: 2024-07-09 09:15:02 UTC
OpenVPN 2.6.10 and earlier in a server role accepts multiple exit notifications from authenticated clients which will extend the validity of a closing session References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-28882 https://www.cve.org/CVERecord?id=CVE-2024-28882 https://community.openvpn.net/openvpn/wiki/CVE-2024-28882 https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07634.html
Patch: https://github.com/OpenVPN/openvpn/commit/55bb3260c12bae33b6a8eac73cbb6972f8517411