Skip to content

Latest commit

 

History

History
111 lines (76 loc) · 3.58 KB

File metadata and controls

111 lines (76 loc) · 3.58 KB

Pre-Auth EAP-TLS DoS — SoftEther VPN Developer Edition 5.2.5188

Field Value
Product SoftEther VPN Developer Edition
Affected Version ≤ 5.2.5188
Patched Version None (fix proposed)
CWE CWE-789: Memory Allocation with Excessive Size Value
CVSS v3.1 7.5 High — AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
GHSA GHSA-q5g3-qhc6-pr3h
CVE Pending
Disclosed 2026-04-05

Summary

An unauthenticated remote attacker can crash the SoftEther VPN vpnserver process by sending a single malformed EAP-TLS packet over raw L2TP (UDP/1701). The crash drops all active VPN sessions. No credentials are required.


Root Cause

Location: src/Cedar/Proto_PPP.c, PPPProcessEAPTlsResponse(), line 3651

During EAP-TLS fragment reassembly, the server reads a 32-bit TlsLength field directly from the attacker-controlled packet header and passes it to ZeroMalloc() with no upper bound check:

// Proto_PPP.c:3617
UINT tlsLength = Endian32(eap_packet->Tls.TlsDataWithLength.TlsLength);

// Proto_PPP.c:3651 — no bounds check
p->Eap_TlsCtx.CachedBufferRecv = ZeroMalloc(MAX(dataSize, tlsLength));

MallocEx() (called by ZeroMalloc) enforces a hard maximum of 0xFFFFFFBF bytes. When tlsLength = 0xFFFFFFFF, the size check fails and AbortExitEx() is called, terminating the entire vpnserver process.


Reachability

The vulnerability is pre-authentication because:

  1. Raw L2TP mode (no IPsec) allows direct access to UDP/1701 with no encryption requirement.
  2. Even with IPsec, the default PSK is "vpn" (hardcoded at src/Cedar/Proto_IPsec.h:36), publicly documented.

Attack Sequence

~11–12 UDP packets to UDP/1701, zero credentials required:

SCCRQ → SCCRP → SCCCN          (L2TP tunnel setup)
ICRQ → ICRP → ICCN             (L2TP session setup)
LCP Config-Request/Config-Ack  (PPP negotiation)
EAP-Response/Identity          (attacker sends any username)
← EAP-Request/TLS Start        (server initiates EAP-TLS)
EAP-Response/TLS               (attacker: Flags=0xC0, TlsLength=0xFFFFFFFF)
→ vpnserver crashes

Crash output:

Fatal Error: MallocEx() error: too large size

Impact

  • Single exploit attempt crashes vpnserver, dropping all active sessions.
  • Watchdog restarts the process in 3–5 seconds, but a sustained flood causes persistent DoS at the restart interval.
  • Attack works with zero prior knowledge of the target over the public internet.

Suggested Fix

Add an upper bound check on tlsLength before the ZeroMalloc() call:

#define MAX_EAP_TLS_REASSEMBLY_SIZE (16 * 1024 * 1024) // 16 MB

if (tlsLength > MAX_EAP_TLS_REASSEMBLY_SIZE) {
    PPP_LOG(p, "EAP-TLS: TlsLength too large (%u), rejecting fragment", tlsLength);
    PPPSetStatus(p, PPP_STATUS_FAIL);
    return false;
}
p->Eap_TlsCtx.CachedBufferRecv = ZeroMalloc(MAX(dataSize, tlsLength));

Additionally, generate a random default IPsec PSK at installation time rather than using the hardcoded "vpn".


Timeline

Date Event
2026-03-XX Vulnerability discovered in lab
2026-04-05 Disclosed to maintainer via GitHub PVR
2026-04-05 Advisory published
Pending CVE assigned

References