Skip to content

fix(openvpn): CVE-2025-13086#7

Open
deepin-ci-robot wants to merge 1 commit into
masterfrom
fix/CVE-2025-10680
Open

fix(openvpn): CVE-2025-13086#7
deepin-ci-robot wants to merge 1 commit into
masterfrom
fix/CVE-2025-10680

Conversation

@deepin-ci-robot
Copy link
Copy Markdown
Contributor

CVE Fix

CVE-2025-13086

  • Vulnerability: Fix inverted memcmp check for HMAC verification in the 3-way handshake, which allowed source IP address validation bypass.
  • Impact: OpenVPN 2.6.0 through 2.6.15 - improper validation of source IP addresses allows an attacker to open a session from a different IP address which did not initiate the connection resulting in a denial of service for the originating client.
  • Strategy: patch (backport upstream commit)
  • Upstream: OpenVPN/openvpn@fa6a182

Not-affected CVEs

  • CVE-2025-10680: Affects 2.7_alpha1 to 2.7_beta1 only (current version 2.6.14 is below affected range)
  • CVE-2025-12106: Affects 2.7_alpha1 to 2.7_rc1 only (current version 2.6.14 is below affected range)
  • CVE-2025-13751: Windows-only vulnerability (interactive service agent)
  • CVE-2025-15497: Affects 2.7_alpha1 to 2.7_rc5 only (current version 2.6.14 is below affected range)

Generated-By: glm-5.1
Co-Authored-By: hudeng hudeng@deepin.org

@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 16, 2026

TAG Bot

TAG: 2.6.14-3deepin1
EXISTED: no
DISTRIBUTION: unstable

@deepin-ci-robot
Copy link
Copy Markdown
Contributor Author

/hold
因为该quilt包的上游版本号变更,详情见: deepin-community/infra-settings#134

@deepin-ci-robot
Copy link
Copy Markdown
Contributor Author

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign liujianqiang-niu for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

- Fix inverted memcmp check for HMAC verification in 3-way handshake
- Add deepin changelog entry with correct version suffix
- Resolve patch conflicts via quilt refresh

Co-authored-by: hudeng <hudeng@deepin.org>
@hudeng-go
Copy link
Copy Markdown

/integrate

@github-actions
Copy link
Copy Markdown

AutoIntegrationPr Bot
auto integrate with pr url: deepin-community/Repository-Integration#4043
PrNumber: 4043
PrBranch: auto-integration-26137216176

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants