Commit f1b851d
socket: reject mismatched address family in get_addr_generic
Add a family check to prevent copying address data of the wrong type,
which could cause buffer over-read when parsing routes or endpoints.
CVE: 2025-12106
Github: OpenVPN/openvpn-private-issues#77
Signed-off-by: Mikhail Khachaiants <mkhachaiants@gmail.com>
Acked-By: Gert Doering <gert@greenie.muc.de>
Signed-Off-By: Gert Doering <gert@greenie.muc.de>1 parent 5ab76ad commit f1b851d
1 file changed
+7
-0
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
147 | 147 | | |
148 | 148 | | |
149 | 149 | | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
150 | 157 | | |
151 | 158 | | |
152 | 159 | | |
| |||
0 commit comments