CVE-2025-24356

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-24356
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-24356.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-24356
Aliases
  • GHSA-pggg-vpfv-4rcv
Related
Published
2025-01-27T18:15:41Z
Modified
2025-02-01T05:47:47.809553Z
Summary
[none]
Details

fastd is a VPN daemon which tunnels IP packets and Ethernet frames over UDP. When receiving a data packet from an unknown IP address/port combination, fastd will assume that one of its connected peers has moved to a new address and initiate a reconnect by sending a handshake packet. This "fast reconnect" avoids having to wait for a session timeout (up to ~90s) until a new connection is established. Even a 1-byte UDP packet just containing the fastd packet type header can trigger a much larger handshake packet (~150 bytes of UDP payload). Including IPv4 and UDP headers, the resulting amplification factor is roughly 12-13. By sending data packets with a spoofed source address to fastd instances reachable on the internet, this amplification of UDP traffic might be used to facilitate a Distributed Denial of Service attack. This vulnerability is fixed in v23.

References

Affected packages

Debian:11 / fastd

Package

Name
fastd
Purl
pkg:deb/debian/fastd?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

Other

21-1
22-1
22-2~bpo10+1
22-2~bpo11+1
22-2
22-3
22-4~bpo11+1
22-4
23-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / fastd

Package

Name
fastd
Purl
pkg:deb/debian/fastd?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

Other

22-4
23-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / fastd

Package

Name
fastd
Purl
pkg:deb/debian/fastd?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
23-1

Affected versions

Other

22-4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/neocturne/fastd

Affected versions

v0.*

v0.1
v0.1-rc1
v0.1-rc2
v0.1-rc3
v0.1-rc4
v0.2
v0.3
v0.4
v0.4-rc1
v0.4-rc10
v0.4-rc11
v0.4-rc12
v0.4-rc13
v0.4-rc2
v0.4-rc3
v0.4-rc4
v0.4-rc5
v0.4-rc6
v0.4-rc7
v0.4-rc8
v0.4-rc9
v0.5
v0.5-rc1
v0.5-rc2
v0.5-rc3
v0.5-rc4

Other

v10
v11
v12
v13
v14
v15
v16
v17
v18
v19
v20
v21
v22
v6
v6-rc1
v7
v8
v9