https://seclists.org/oss-sec/2025/q2/8: CVE-2025-2704 - OpenVPN 2.6.1 through 2.6.13 with possible DoS
Published Apr 2, 2025
·Updated
Affected Software
1 affected component
OpenVPN OpenVPN>=2.6.1<2.6.13
Frequently Asked Questions
1
What is the severity of CVE-2025-2704?
CVE-2025-2704 is classified as a critical vulnerability due to its potential to cause denial of service in OpenVPN servers.
2
How do I fix CVE-2025-2704?
To resolve CVE-2025-2704, upgrade to OpenVPN version 2.6.14 or later.
3
What versions of OpenVPN are affected by CVE-2025-2704?
CVE-2025-2704 affects OpenVPN versions 2.6.1 through 2.6.13.
4
What is the nature of the vulnerability in CVE-2025-2704?
The vulnerability in CVE-2025-2704 may lead to a potential denial of service via an ASSERT() failure on OpenVPN servers.
5
When was CVE-2025-2704 published?
CVE-2025-2704 was published on April 2, 2025.