[Openvpn-devel,v2] options: fix unsigned underflow when clearing domain_search_list
| Message ID | 20260913132322.2283-1-gert@greenie.muc.de |
|---|---|
| State | New |
| Headers |
Return-Path: <openvpn-devel-bounces@lists.sourceforge.net>
Delivered-To: patchwork@openvpn.net
Received: by 2002:a05:7000:6446:b0:8a0:ea1f:253a with SMTP id n6csp2560407mag;
Sun, 13 Sep 2026 06:23:36 -0700 (PDT)
X-Forwarded-Encrypted: i=2;
AKwUvBwDwSaHV7A/lkV0tm3oxVB52C4TVDCMZ+VVtoOpd7TejZ0BIuEn5dxLm5rncKT64g5XyhFPb5cogZc=@openvpn.net
X-Received: by 2002:a05:6808:2f09:b0:4c5:7d0d:7a5f with SMTP id
5614622812f47-4c57d0d87e3mr2691159b6e.6.1789305816750;
Sun, 13 Sep 2026 06:23:36 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1789305816; cv=none;
d=google.com; s=arc-20260327;
b=RZaR8iFiOlpMirZzDrfsrkKcqiuJt6MF/SNiq37yL0W2IiE9bubIwXZmDp911fv+J8
Om2+A1v3kFfN8tAQTNYdbc7dpvG+Cv+y+Ry4bOzMFLaTK/jDdUyblHUQ2pHAOE+LqgHd
dV7xslEtWBdyUOnGaE7ls5bV+avz0tju6IyrljgXg/8bl3e3DKCHLUJvhb1UupwA6FEA
gjIB3AHaVhuzippg35ptUH39Xz+I1muHlX1dixHLiU3HxK95wPjNVc7mKCup1Ooequep
0pEIUYAasmA43a40EngOPey3RUAM8lDpucOOi+VdGMAmuctDauT0AHfdqJQbj4SzPDHp
dmog==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com;
s=arc-20260327;
h=errors-to:content-transfer-encoding:list-subscribe:list-help
:list-post:list-archive:list-unsubscribe:list-id:precedence:subject
:mime-version:references:in-reply-to:message-id:date:to:from
:dkim-signature:dkim-signature:dkim-signature;
bh=i7iPv5z8RY/cHZDb7sCXV0vYZ1aGC4tAnZMVZZBJQKA=;
fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=;
b=NHXj0awO0D7Dj4eW3W7p5qecZRXp5094ffGFy7n004OUsQge0TJBJu+reJgVNFWnvh
xFPfwf/kdQq/g8x+7LM+L4+5Kl+kyKVZSY9H3x+g4xdOGRv4cyp3wvKGOOjTi0mZYSMC
getC/Iet8ah+7Sc4BflN2J+CnKapQrGVeOtktozqTIdW2G1IejipAlN/gTLuoIUBxCTi
xGcQc4k1hBt1o3GTVUMPo3D5Hujsm2t7WhXJmcZ+C3rXwwnRBAWGJspTon+Qo3oUCHkg
x4KT3xUUhzin05CIDRY8VTMeY+toGuZXxuSu6T35IMkgYLUWg7PtuiN53XNICWNAsgmx
d4aw==;
dara=google.com
ARC-Authentication-Results: i=1; mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b=XuaLSWyc;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b=f2azQKpi;
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b="Z/ZbJv6M";
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net;
dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de
Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7])
by mx.google.com with ESMTPS id
5614622812f47-4c331bc6115si7777063b6e.90.2026.09.13.06.23.36
(version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
Sun, 13 Sep 2026 06:23:36 -0700 (PDT)
Received-SPF: pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) client-ip=216.105.38.7;
Authentication-Results: mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b=XuaLSWyc;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b=f2azQKpi;
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b="Z/ZbJv6M";
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net;
dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type:
List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id:
Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender:
Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From:
Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner;
bh=i7iPv5z8RY/cHZDb7sCXV0vYZ1aGC4tAnZMVZZBJQKA=; b=XuaLSWyc52FggVYEDyic3+oKrb
bGDQdFRzZSaow0a58gMqkaulbws1ychp+EujBIH6mFQC1Cqix8wFWiz5nG0sc/u1p/liG+r4mM9PA
FdJ55ilCxQruMZwnt342zUiVrDUam+K6G84PQwEuGlyl90ItUbYpH/nw95lZ8+G26/ic=;
Received: from [127.0.0.1] (helo=sfs-ml-2.v29.lw.sourceforge.com)
by sfs-ml-2.v29.lw.sourceforge.com with esmtp (Exim 4.95)
(envelope-from <openvpn-devel-bounces@lists.sourceforge.net>)
id 1x5kB9-0000Wz-5G;
Sun, 13 Sep 2026 13:23:31 +0000
Received: from [172.30.29.66] (helo=mx.sourceforge.net)
by sfs-ml-2.v29.lw.sourceforge.com with esmtps (TLS1.2) tls
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95)
(envelope-from <gert@blue4.greenie.muc.de>) id 1x5kB8-0000Wt-BU
for openvpn-devel@lists.sourceforge.net;
Sun, 13 Sep 2026 13:23:31 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References:
In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:
Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender:
Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:
List-Subscribe:List-Post:List-Owner:List-Archive;
bh=1hPkNIUxlgxTGy3flRcX6H0+pgpGWZrqb8I5G1UF+2U=; b=f2azQKpiHA81jfKAEgG2lwxBDF
mIygIsH22wklfk8SoKENA4oD9ABlMltFRFi6NdMi0lyiNCoiMSv4lF6B/trJKzZhqiXG9uqAuJcg6
1ALyPFYF+mlUR2HmDAuRVLIt0CzzycqqaSW/Xs7WjtmSDgqN3XK/AgyHAQJNZumGYRKQ=;
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x
;
h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID:
Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID:
Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc
:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe:
List-Post:List-Owner:List-Archive;
bh=1hPkNIUxlgxTGy3flRcX6H0+pgpGWZrqb8I5G1UF+2U=; b=Z/ZbJv6MVwUGB6q/1IJ+Ao8Esk
uVtA9LAIX5FsBBUwsErvwgo0z3eh13kFXVObXecL5sUKrcoonvtfF/PamxKSyhCNY0UXIT8/v5C/r
ey5c5QdVZkkdjpOwPuheAb+aVKUvtdPauBG+vem+8tg9KE9aTU3lA298w/UtKXzTnhk4=;
Received: from [193.149.48.129] (helo=blue.greenie.muc.de)
by sfi-mx-2.v28.lw.sourceforge.com with esmtps
(TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95)
id 1x5kB7-0000kj-VZ for openvpn-devel@lists.sourceforge.net;
Sun, 13 Sep 2026 13:23:31 +0000
Received: from blue.greenie.muc.de (localhost [127.0.0.1])
by blue.greenie.muc.de (8.18.1/8.18.1) with ESMTP id 68DDNMLb002299
for <openvpn-devel@lists.sourceforge.net>; Sun, 13 Sep 2026 15:23:22 +0200
Received: (from gert@localhost)
by blue.greenie.muc.de (8.18.2/8.18.1/Submit) id 68DDNMIR002298
for openvpn-devel@lists.sourceforge.net; Sun, 13 Sep 2026 15:23:22 +0200
From: Gert Doering <gert@greenie.muc.de>
To: openvpn-devel@lists.sourceforge.net
Date: Sun, 13 Sep 2026 15:23:17 +0200
Message-ID: <20260913132322.2283-1-gert@greenie.muc.de>
X-Mailer: git-send-email 2.53.0
In-Reply-To:
<gerrit.1789291650000.I3724236d4acc3d05d786274d6baf34a21c570594@gerrit.openvpn.net>
References:
<gerrit.1789291650000.I3724236d4acc3d05d786274d6baf34a21c570594@gerrit.openvpn.net>
MIME-Version: 1.0
X-Spam-Score: 1.3 (+)
X-Spam-Report: Spam detection software,
running on the system "sfi-spamd-2.hosts.colo.sdot.me",
has NOT identified this incoming email as spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: From: Cole Munz <Munzzyy1@proton.me> remove_option() and
update_option()
clear the domain search list with while (o->domain_search_list_len-- > 0)
Content analysis details: (1.3 points, 5.0 required)
pts rule name description
---- ----------------------
--------------------------------------------------
1.3 RDNS_NONE Delivered to internal network by a host with no rDNS
X-Headers-End: 1x5kB7-0000kj-VZ
Subject: [Openvpn-devel] [PATCH v2] options: fix unsigned underflow when
clearing domain_search_list
X-BeenThere: openvpn-devel@lists.sourceforge.net
X-Mailman-Version: 2.1.21
Precedence: list
List-Id: <openvpn-devel.lists.sourceforge.net>
List-Unsubscribe: <https://lists.sourceforge.net/lists/options/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=unsubscribe>
List-Archive:
<http://sourceforge.net/mailarchive/forum.php?forum_name=openvpn-devel>
List-Post: <mailto:openvpn-devel@lists.sourceforge.net>
List-Help: <mailto:openvpn-devel-request@lists.sourceforge.net?subject=help>
List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: openvpn-devel-bounces@lists.sourceforge.net
X-getmail-retrieved-from-mailbox: Inbox
X-GMAIL-THRID: 1876223136064740167
X-GMAIL-MSGID: 1876223136064740167
|
| Series |
[Openvpn-devel,v2] options: fix unsigned underflow when clearing domain_search_list
|
|
Commit Message
Gert Doering
Sept. 13, 2026, 1:23 p.m. UTC
From: Cole Munz <Munzzyy1@proton.me> remove_option() and update_option() clear the domain search list with while (o->domain_search_list_len-- > 0) domain_search_list_len is unsigned, and the post-decrement runs on the final test too. When the length reaches 0 the condition is false but the decrement has already wrapped it to UINT_MAX, so the field is left corrupted. The next reset then does o->domain_search_list[UINT_MAX] = NULL and walks far out of bounds, writing NULL through each slot. A server can drive this reset path against a client with PUSH_UPDATE, so on Windows and Android this is a remotely reachable out-of-bounds write. v2: Change to the semantics used for all the other lists there - set length to 0 and clear the list with CLEAR(). Change-Id: I3724236d4acc3d05d786274d6baf34a21c570594 Signed-off-by: Cole Munz <Munzzyy1@proton.me> Acked-by: Razvan Cojocaru <razvanc@mailbox.org> Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1914 Github: OpenVPN/openvpn-private-issues#178 CVE: 2026-88964 --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge it to master. Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1914 This mail reflects revision 2 of this Change. Acked-by according to Gerrit (reflected above): Razvan Cojocaru <razvanc@mailbox.org>
diff --git a/src/openvpn/options.c b/src/openvpn/options.c index 25a3746..f6a5fe4 100644 --- a/src/openvpn/options.c +++ b/src/openvpn/options.c @@ -3778,12 +3778,12 @@ memset(o->ntp, 0, sizeof(o->ntp)); o->nbdd_len = 0; memset(o->nbdd, 0, sizeof(o->nbdd)); - while (o->domain_search_list_len-- > 0) - { - o->domain_search_list[o->domain_search_list_len] = NULL; - } + o->domain_search_list_len = 0; + CLEAR(o->domain_search_list); o->disable_nbt = 0; o->dhcp_options = 0; + CLEAR(options->dns_options.from_dhcp); + #if defined(TARGET_ANDROID) o->http_proxy_port = 0; o->http_proxy = NULL; @@ -4082,10 +4082,8 @@ CLEAR(o->ntp); o->nbdd_len = 0; CLEAR(o->nbdd); - while (o->domain_search_list_len-- > 0) - { - o->domain_search_list[o->domain_search_list_len] = NULL; - } + o->domain_search_list_len = 0; + CLEAR(o->domain_search_list); o->disable_nbt = 0; o->dhcp_options = 0;