| Field | Value |
|---|---|
| Product | SoftEther VPN Developer Edition |
| Affected Version | ≤ 5.2.5188 |
| Patched Version | None (fix proposed) |
| CWE | CWE-789: Memory Allocation with Excessive Size Value |
| CVSS v3.1 | 7.5 High — AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| GHSA | GHSA-q5g3-qhc6-pr3h |
| CVE | Pending |
| Disclosed | 2026-04-05 |
An unauthenticated remote attacker can crash the SoftEther VPN vpnserver process by sending a single malformed EAP-TLS packet over raw L2TP (UDP/1701). The crash drops all active VPN sessions. No credentials are required.
Location: src/Cedar/Proto_PPP.c, PPPProcessEAPTlsResponse(), line 3651
During EAP-TLS fragment reassembly, the server reads a 32-bit TlsLength field directly from the attacker-controlled packet header and passes it to ZeroMalloc() with no upper bound check:
// Proto_PPP.c:3617
UINT tlsLength = Endian32(eap_packet->Tls.TlsDataWithLength.TlsLength);
// Proto_PPP.c:3651 — no bounds check
p->Eap_TlsCtx.CachedBufferRecv = ZeroMalloc(MAX(dataSize, tlsLength));MallocEx() (called by ZeroMalloc) enforces a hard maximum of 0xFFFFFFBF bytes. When tlsLength = 0xFFFFFFFF, the size check fails and AbortExitEx() is called, terminating the entire vpnserver process.
The vulnerability is pre-authentication because:
- Raw L2TP mode (no IPsec) allows direct access to UDP/1701 with no encryption requirement.
- Even with IPsec, the default PSK is
"vpn"(hardcoded atsrc/Cedar/Proto_IPsec.h:36), publicly documented.
~11–12 UDP packets to UDP/1701, zero credentials required:
SCCRQ → SCCRP → SCCCN (L2TP tunnel setup)
ICRQ → ICRP → ICCN (L2TP session setup)
LCP Config-Request/Config-Ack (PPP negotiation)
EAP-Response/Identity (attacker sends any username)
← EAP-Request/TLS Start (server initiates EAP-TLS)
EAP-Response/TLS (attacker: Flags=0xC0, TlsLength=0xFFFFFFFF)
→ vpnserver crashes
Crash output:
Fatal Error: MallocEx() error: too large size
- Single exploit attempt crashes vpnserver, dropping all active sessions.
- Watchdog restarts the process in 3–5 seconds, but a sustained flood causes persistent DoS at the restart interval.
- Attack works with zero prior knowledge of the target over the public internet.
Add an upper bound check on tlsLength before the ZeroMalloc() call:
#define MAX_EAP_TLS_REASSEMBLY_SIZE (16 * 1024 * 1024) // 16 MB
if (tlsLength > MAX_EAP_TLS_REASSEMBLY_SIZE) {
PPP_LOG(p, "EAP-TLS: TlsLength too large (%u), rejecting fragment", tlsLength);
PPPSetStatus(p, PPP_STATUS_FAIL);
return false;
}
p->Eap_TlsCtx.CachedBufferRecv = ZeroMalloc(MAX(dataSize, tlsLength));Additionally, generate a random default IPsec PSK at installation time rather than using the hardcoded "vpn".
| Date | Event |
|---|---|
| 2026-03-XX | Vulnerability discovered in lab |
| 2026-04-05 | Disclosed to maintainer via GitHub PVR |
| 2026-04-05 | Advisory published |
| Pending | CVE assigned |