| Message ID | 20260830182134.32251-1-gert@greenie.muc.de |
|---|---|
| State | New |
| Headers |
Return-Path: <openvpn-devel-bounces@lists.sourceforge.net>
Delivered-To: patchwork@openvpn.net
Received: by 2002:a05:7000:c317:b0:87d:ab56:3700 with SMTP id
jk23csp2331177mab;
Sun, 30 Aug 2026 11:21:49 -0700 (PDT)
X-Forwarded-Encrypted: i=2;
AHgh+RpLTZhLRxEtrezB8qbf7q0Wcwve3vUy2EA9Kdp+pA6fWbwRWQlGUSutFQbCdGRpqT0Mv7z5fR1/q7I=@openvpn.net
X-Received: by 2002:a05:6808:514a:b0:4b3:1a95:42d8 with SMTP id
5614622812f47-4b397fa355fmr24606323b6e.8.1788114108925;
Sun, 30 Aug 2026 11:21:48 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1788114108; cv=none;
d=google.com; s=arc-20260327;
b=B4ZdEJFn6rXgQypOip+OG6mmaawWr0ryqb0q0MeS2PFRu7FKs7hP5xf+2nK/6sL4y5
F80+ixfVQkMfRnsLm32+m7kE1mq9wVEjQiHWaja7i1Do9PcJ74vDeLJQa14uyBVpBqtx
hqZp45mrTJPN0O+shWAm5kdTZABI/1nFupNQr8FhTlGGwZ+30aGe2gHMmgkEzJteAeFK
uPk95tHtv9C1S0kZUHvbB6fvoFShexFDDzlmG2YsvJZRVwi0SgWLEt2pbRM+9b3I0dWT
wg0cJj3ouTOb34Qm/VlHFvTI4ejXB5/bVVb5JO77bgzmlKzzERdMdBAhFPDlAQruQ4Uf
27Qg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com;
s=arc-20260327;
h=errors-to:content-transfer-encoding:list-subscribe:list-help
:list-post:list-archive:list-unsubscribe:list-id:precedence:subject
:mime-version:references:in-reply-to:message-id:date:to:from
:dkim-signature:dkim-signature:dkim-signature;
bh=t/xk8RfJqAKoRHIteztoszF7JCxp7rTDBRg67+n0LLA=;
fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=;
b=ITWt8TqHv2sq2aEMExXIJlmUuJafj+MOd9MLSbl0U4YSvVseY3Y1iZK/pow7lJvaDz
YRXY5hKg2uzJEdSSBdoXN1wzBHMkqoLs2zOOUhV9+XazMNAod5NObd7YTxthuQGgI96l
PaqZaPn5Tb5d3DHc8JyHmZEVU9ps+7817Hfjn0dlHsGYKgsjdrRn5Rdl/W0lskrGebvN
+3XKXltTPJb7sTn5qQP2/KAjWB3bKjG/PpjNpO0t/VHi86xl2N9HLOrQxDVG2yLSRgV9
Df2mdwQRiZtZiC5KyMOU+rcH7bJTdATFP1FNhNDzOod75TZkBjPJYLCxJCxIAY65L5Af
hehQ==;
dara=google.com
ARC-Authentication-Results: i=1; mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b=IDQuO0V7;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b=SpxxjiTp;
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=l7qyEwno;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net;
dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de
Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7])
by mx.google.com with ESMTPS id
5614622812f47-4b3a16c3e7dsi12432117b6e.36.2026.08.30.11.21.48
(version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
Sun, 30 Aug 2026 11:21:48 -0700 (PDT)
Received-SPF: pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) client-ip=216.105.38.7;
Authentication-Results: mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b=IDQuO0V7;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b=SpxxjiTp;
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=l7qyEwno;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net;
dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type:
List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id:
Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender:
Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From:
Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner;
bh=t/xk8RfJqAKoRHIteztoszF7JCxp7rTDBRg67+n0LLA=; b=IDQuO0V7PusYPoXaihhz3umadN
2BfONjePflaKZoWKvE82dIjvhwubhFIz7ZqOcEnwJm8Le/Mcl1zCCbbQ1yQUH9bEJQ1WqQB0GqJB3
sKZW6Z42pcrD1kJldEXxVE1OK3xDPw38xtCZnkK5vk29XsXqA+RM3lyHzdVjli8xyh+c=;
Received: from [127.0.0.1] (helo=sfs-ml-4.v29.lw.sourceforge.com)
by sfs-ml-4.v29.lw.sourceforge.com with esmtp (Exim 4.95)
(envelope-from <openvpn-devel-bounces@lists.sourceforge.net>)
id 1x0kA4-0006Ox-Ja;
Sun, 30 Aug 2026 18:21:44 +0000
Received: from [172.30.29.66] (helo=mx.sourceforge.net)
by sfs-ml-4.v29.lw.sourceforge.com with esmtps (TLS1.2) tls
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95)
(envelope-from <gert@blue4.greenie.muc.de>) id 1x0kA2-0006Oq-TB
for openvpn-devel@lists.sourceforge.net;
Sun, 30 Aug 2026 18:21:42 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References:
In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:
Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender:
Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:
List-Subscribe:List-Post:List-Owner:List-Archive;
bh=AJVkQbYirw5Bz2LYrRLVUcNjDlivlFTkwAskazo1ezk=; b=SpxxjiTpHYEJFlsvLk7EYZhWX9
nIGivLIMPVbszWWy3xgTViQfdKYXJcK3Rp97/R7RwUetNqVAO7XwKc/fYb+2tmvLHrsa3XsBWq8Xe
zcRXR67Cq3ZK9PD9f+CV8WQbnciLgso2i0oY3hKJtc4X3U/8i/daDso7vhMjlIv8ZGu4=;
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x
;
h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID:
Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID:
Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc
:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe:
List-Post:List-Owner:List-Archive;
bh=AJVkQbYirw5Bz2LYrRLVUcNjDlivlFTkwAskazo1ezk=; b=l7qyEwno8SkC2biHT29WW1aulC
8WSWTDdwS2yfF68yJFdIIER3QojvttwWZNJJVqTw7pgWsMHz8gjlL7b3NYRvwFIsUsvMOjjizQ7rQ
7Qhy5v3iWc1z89CH4Ga+T2KyniJdafKpEOGDCbyeqh81odN7M+8MWdNpiwGu/570li+w=;
Received: from [193.149.48.129] (helo=blue.greenie.muc.de)
by sfi-mx-2.v28.lw.sourceforge.com with esmtps
(TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95)
id 1x0kA1-0002lH-QJ for openvpn-devel@lists.sourceforge.net;
Sun, 30 Aug 2026 18:21:42 +0000
Received: from blue.greenie.muc.de (localhost [127.0.0.1])
by blue.greenie.muc.de (8.18.1/8.18.1) with ESMTP id 67UILYHG032284
for <openvpn-devel@lists.sourceforge.net>; Sun, 30 Aug 2026 20:21:34 +0200
Received: (from gert@localhost)
by blue.greenie.muc.de (8.18.2/8.18.1/Submit) id 67UILYen032283
for openvpn-devel@lists.sourceforge.net; Sun, 30 Aug 2026 20:21:34 +0200
From: Gert Doering <gert@greenie.muc.de>
To: openvpn-devel@lists.sourceforge.net
Date: Sun, 30 Aug 2026 20:21:27 +0200
Message-ID: <20260830182134.32251-1-gert@greenie.muc.de>
X-Mailer: git-send-email 2.53.0
In-Reply-To:
<gerrit.1788113537000.Ica5d43989b441d4377a3908f811a2953b7a9d45a@gerrit.openvpn.net>
References:
<gerrit.1788113537000.Ica5d43989b441d4377a3908f811a2953b7a9d45a@gerrit.openvpn.net>
MIME-Version: 1.0
X-Spam-Score: 1.3 (+)
X-Spam-Report: Spam detection software,
running on the system "sfi-spamd-1.hosts.colo.sdot.me",
has NOT identified this incoming email as spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: From: Heiko Hund <heiko@ist.eigentlich.net> If the
config_dir
value in the registry has no trailing backslash the check doesn't actually
guarantee that a file is located within config_dir, because a sibling dir
with the same prefix, e.g. 'confi [...]
Content analysis details: (1.3 points, 5.0 required)
pts rule name description
---- ----------------------
--------------------------------------------------
1.3 RDNS_NONE Delivered to internal network by a host with no rDNS
X-Headers-End: 1x0kA1-0002lH-QJ
Subject: [Openvpn-devel] [PATCH v1] openvpnserv: detect sibling dirs in
CheckConfigPath
X-BeenThere: openvpn-devel@lists.sourceforge.net
X-Mailman-Version: 2.1.21
Precedence: list
List-Id: <openvpn-devel.lists.sourceforge.net>
List-Unsubscribe: <https://lists.sourceforge.net/lists/options/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=unsubscribe>
List-Archive:
<http://sourceforge.net/mailarchive/forum.php?forum_name=openvpn-devel>
List-Post: <mailto:openvpn-devel@lists.sourceforge.net>
List-Help: <mailto:openvpn-devel-request@lists.sourceforge.net?subject=help>
List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: openvpn-devel-bounces@lists.sourceforge.net
X-getmail-retrieved-from-mailbox: Inbox
X-GMAIL-THRID: 1874973539614350762
X-GMAIL-MSGID: 1874973539614350762
|
| Series |
[Openvpn-devel,v1] openvpnserv: detect sibling dirs in CheckConfigPath
|
|
Commit Message
Gert Doering
Aug. 30, 2026, 6:21 p.m. UTC
From: Heiko Hund <heiko@ist.eigentlich.net> If the config_dir value in the registry has no trailing backslash the check doesn't actually guarantee that a file is located within config_dir, because a sibling dir with the same prefix, e.g. 'config' and 'config-evil' will match and produce a positive verdict. By also checking that there is a path separator after config_dir prevents this attack. Reported-By: Harshit Varu <harshitvaru666@gmail.com> Tested-By: Harshit Varu <harshitvaru666@gmail.com> CVE: 2026-81830 Github: OpenVPN/openvpn-private-issues#166 Change-Id: Ica5d43989b441d4377a3908f811a2953b7a9d45a Signed-off-by: Heiko Hund <heiko@ist.eigentlich.net> Acked-by: Razvan Cojocaru <razvanc@mailbox.org> Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1883 --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge it to release/2.6. Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1883 This mail reflects revision 1 of this Change. Acked-by according to Gerrit (reflected above): Razvan Cojocaru <razvanc@mailbox.org>
Comments
This is, basically, a simplified backport of the fix that went into
"what became 2.7.0" - we did not do 2.6 at the time because the 2.7 fix
used a newer windows API that would have broken in-train compat for
2.6 (and then we forgot about it).
Arne's ACK was reported in the private GH repo, Razvan's both in Gerrit
and GH. Harshit Varu reported this to us, and confirmed the patch fixes
the issue. Thanks :-)
Your patch has been applied to the release/2.6 branch.
commit 927b18dff00a8ec0e9233a9689569e4519fc7de6 (release/2.6)
Author: Heiko Hund
Date: Sun Aug 30 20:21:27 2026 +0200
openvpnserv: detect sibling dirs in CheckConfigPath
Signed-off-by: Heiko Hund <heiko@ist.eigentlich.net>
Acked-by: Razvan Cojocaru <razvanc@mailbox.org>
Acked-by: Arne Schwabe <arne@rfc2549.org>
Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1883
Message-Id: <20260830182134.32251-1-gert@greenie.muc.de>
URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg38828.html
Signed-off-by: Gert Doering <gert@greenie.muc.de>
--
kind regards,
Gert Doering
diff --git a/src/openvpnserv/validate.c b/src/openvpnserv/validate.c index 770a7a0..b0fb6b85 100644 --- a/src/openvpnserv/validate.c +++ b/src/openvpnserv/validate.c @@ -56,7 +56,9 @@ /* * Check workdir\fname is inside config_dir - * The logic here is simple: we may reject some valid paths if ..\ is in any of the strings + * The logic here is simple: + * we may reject some valid paths if ".." is in the filename + * or if there's no "\" after the config directory */ static BOOL CheckConfigPath(const WCHAR *workdir, const WCHAR *fname, const settings_t *s) @@ -82,9 +84,18 @@ } config_dir = s->config_dir; + size_t config_dir_len = wcslen(config_dir); - if (wcsncmp(config_dir, config_file, wcslen(config_dir)) == 0 - && wcsstr(config_file + wcslen(config_dir), L"..") == NULL) + /* check for a path separator after config_dir */ + if (config_dir_len && config_dir_len < wcslen(config_file) + && config_dir[config_dir_len - 1] != L'\\' + && config_file[config_dir_len] != L'\\') + { + return FALSE; + } + + if (wcsncmp(config_dir, config_file, config_dir_len) == 0 + && wcsstr(config_file + config_dir_len, L"..") == NULL) { return TRUE; }