Remote service crash via misaligned OpenVPN probe access
Published Jun 2, 2025 · Updated Jun 2, 2025
Out-of-range pointer access in Yves Rutschle sslh before 2.2.4 allows remote attackers to crash the daemon with crafted UDP data. The UDP path in is_openvpn_protocol() casts an offset within the heap-backed network buffer to uint32_t* and dereferences it without alignment safety. The crash occurs on strict-alignment architectures such as ARM when the OpenVPN probe is enabled, interrupting multiplexed services.
Summary
What happened
Out-of-range pointer access in Yves Rutschle sslh before 2.2.4 allows remote attackers to crash the daemon with crafted UDP data. The UDP path in is_openvpn_protocol() casts an offset within the heap-backed network buffer to uint32_t* and dereferences it without alignment safety. The crash occurs on strict-alignment architectures such as ARM when the OpenVPN probe is enabled, interrupting multiplexed services.
The record
- CVE
- CVE-2025-46806
- Published
- Jun 2, 2025
- Updated
- Jun 2, 2025
- Vendor
- Yves Rutschle
- Product
- sslh
- Classifications
- CWE-823, T1499.004
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Jun 2, 2025CVE publishedPublication date reported by the CVE source.
- Jun 2, 2025Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=? <2.2.4
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- 29-byte UDP OpenVPN probe reproduction sequenceproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo