From patchwork Sun Sep 13 13:23:17 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Gert Doering X-Patchwork-Id: 5337 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:6446:b0:8a0:ea1f:253a with SMTP id n6csp2560407mag; Sun, 13 Sep 2026 06:23:36 -0700 (PDT) X-Forwarded-Encrypted: i=2; AKwUvBwDwSaHV7A/lkV0tm3oxVB52C4TVDCMZ+VVtoOpd7TejZ0BIuEn5dxLm5rncKT64g5XyhFPb5cogZc=@openvpn.net X-Received: by 2002:a05:6808:2f09:b0:4c5:7d0d:7a5f with SMTP id 5614622812f47-4c57d0d87e3mr2691159b6e.6.1789305816750; Sun, 13 Sep 2026 06:23:36 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1789305816; cv=none; d=google.com; s=arc-20260327; b=RZaR8iFiOlpMirZzDrfsrkKcqiuJt6MF/SNiq37yL0W2IiE9bubIwXZmDp911fv+J8 Om2+A1v3kFfN8tAQTNYdbc7dpvG+Cv+y+Ry4bOzMFLaTK/jDdUyblHUQ2pHAOE+LqgHd dV7xslEtWBdyUOnGaE7ls5bV+avz0tju6IyrljgXg/8bl3e3DKCHLUJvhb1UupwA6FEA gjIB3AHaVhuzippg35ptUH39Xz+I1muHlX1dixHLiU3HxK95wPjNVc7mKCup1Ooequep 0pEIUYAasmA43a40EngOPey3RUAM8lDpucOOi+VdGMAmuctDauT0AHfdqJQbj4SzPDHp dmog== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature; bh=i7iPv5z8RY/cHZDb7sCXV0vYZ1aGC4tAnZMVZZBJQKA=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=NHXj0awO0D7Dj4eW3W7p5qecZRXp5094ffGFy7n004OUsQge0TJBJu+reJgVNFWnvh xFPfwf/kdQq/g8x+7LM+L4+5Kl+kyKVZSY9H3x+g4xdOGRv4cyp3wvKGOOjTi0mZYSMC getC/Iet8ah+7Sc4BflN2J+CnKapQrGVeOtktozqTIdW2G1IejipAlN/gTLuoIUBxCTi xGcQc4k1hBt1o3GTVUMPo3D5Hujsm2t7WhXJmcZ+C3rXwwnRBAWGJspTon+Qo3oUCHkg x4KT3xUUhzin05CIDRY8VTMeY+toGuZXxuSu6T35IMkgYLUWg7PtuiN53XNICWNAsgmx d4aw==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=XuaLSWyc; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=f2azQKpi; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b="Z/ZbJv6M"; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 5614622812f47-4c331bc6115si7777063b6e.90.2026.09.13.06.23.36 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Sun, 13 Sep 2026 06:23:36 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=XuaLSWyc; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=f2azQKpi; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b="Z/ZbJv6M"; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=i7iPv5z8RY/cHZDb7sCXV0vYZ1aGC4tAnZMVZZBJQKA=; b=XuaLSWyc52FggVYEDyic3+oKrb bGDQdFRzZSaow0a58gMqkaulbws1ychp+EujBIH6mFQC1Cqix8wFWiz5nG0sc/u1p/liG+r4mM9PA FdJ55ilCxQruMZwnt342zUiVrDUam+K6G84PQwEuGlyl90ItUbYpH/nw95lZ8+G26/ic=; Received: from [127.0.0.1] (helo=sfs-ml-2.v29.lw.sourceforge.com) by sfs-ml-2.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1x5kB9-0000Wz-5G; Sun, 13 Sep 2026 13:23:31 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-2.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1x5kB8-0000Wt-BU for openvpn-devel@lists.sourceforge.net; Sun, 13 Sep 2026 13:23:31 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=1hPkNIUxlgxTGy3flRcX6H0+pgpGWZrqb8I5G1UF+2U=; b=f2azQKpiHA81jfKAEgG2lwxBDF mIygIsH22wklfk8SoKENA4oD9ABlMltFRFi6NdMi0lyiNCoiMSv4lF6B/trJKzZhqiXG9uqAuJcg6 1ALyPFYF+mlUR2HmDAuRVLIt0CzzycqqaSW/Xs7WjtmSDgqN3XK/AgyHAQJNZumGYRKQ=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=1hPkNIUxlgxTGy3flRcX6H0+pgpGWZrqb8I5G1UF+2U=; b=Z/ZbJv6MVwUGB6q/1IJ+Ao8Esk uVtA9LAIX5FsBBUwsErvwgo0z3eh13kFXVObXecL5sUKrcoonvtfF/PamxKSyhCNY0UXIT8/v5C/r ey5c5QdVZkkdjpOwPuheAb+aVKUvtdPauBG+vem+8tg9KE9aTU3lA298w/UtKXzTnhk4=; Received: from [193.149.48.129] (helo=blue.greenie.muc.de) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1x5kB7-0000kj-VZ for openvpn-devel@lists.sourceforge.net; Sun, 13 Sep 2026 13:23:31 +0000 Received: from blue.greenie.muc.de (localhost [127.0.0.1]) by blue.greenie.muc.de (8.18.1/8.18.1) with ESMTP id 68DDNMLb002299 for ; Sun, 13 Sep 2026 15:23:22 +0200 Received: (from gert@localhost) by blue.greenie.muc.de (8.18.2/8.18.1/Submit) id 68DDNMIR002298 for openvpn-devel@lists.sourceforge.net; Sun, 13 Sep 2026 15:23:22 +0200 From: Gert Doering To: openvpn-devel@lists.sourceforge.net Date: Sun, 13 Sep 2026 15:23:17 +0200 Message-ID: <20260913132322.2283-1-gert@greenie.muc.de> X-Mailer: git-send-email 2.53.0 In-Reply-To: References: MIME-Version: 1.0 X-Spam-Score: 1.3 (+) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: From: Cole Munz remove_option() and update_option() clear the domain search list with while (o->domain_search_list_len-- > 0) Content analysis details: (1.3 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 1.3 RDNS_NONE Delivered to internal network by a host with no rDNS X-Headers-End: 1x5kB7-0000kj-VZ Subject: [Openvpn-devel] [PATCH v2] options: fix unsigned underflow when clearing domain_search_list X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1876223136064740167 X-GMAIL-MSGID: 1876223136064740167 From: Cole Munz remove_option() and update_option() clear the domain search list with while (o->domain_search_list_len-- > 0) domain_search_list_len is unsigned, and the post-decrement runs on the final test too. When the length reaches 0 the condition is false but the decrement has already wrapped it to UINT_MAX, so the field is left corrupted. The next reset then does o->domain_search_list[UINT_MAX] = NULL and walks far out of bounds, writing NULL through each slot. A server can drive this reset path against a client with PUSH_UPDATE, so on Windows and Android this is a remotely reachable out-of-bounds write. v2: Change to the semantics used for all the other lists there - set length to 0 and clear the list with CLEAR(). Change-Id: I3724236d4acc3d05d786274d6baf34a21c570594 Signed-off-by: Cole Munz Acked-by: Razvan Cojocaru Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1914 Github: OpenVPN/openvpn-private-issues#178 CVE: 2026-88964 --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge it to master. Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1914 This mail reflects revision 2 of this Change. Acked-by according to Gerrit (reflected above): Razvan Cojocaru diff --git a/src/openvpn/options.c b/src/openvpn/options.c index 25a3746..f6a5fe4 100644 --- a/src/openvpn/options.c +++ b/src/openvpn/options.c @@ -3778,12 +3778,12 @@ memset(o->ntp, 0, sizeof(o->ntp)); o->nbdd_len = 0; memset(o->nbdd, 0, sizeof(o->nbdd)); - while (o->domain_search_list_len-- > 0) - { - o->domain_search_list[o->domain_search_list_len] = NULL; - } + o->domain_search_list_len = 0; + CLEAR(o->domain_search_list); o->disable_nbt = 0; o->dhcp_options = 0; + CLEAR(options->dns_options.from_dhcp); + #if defined(TARGET_ANDROID) o->http_proxy_port = 0; o->http_proxy = NULL; @@ -4082,10 +4082,8 @@ CLEAR(o->ntp); o->nbdd_len = 0; CLEAR(o->nbdd); - while (o->domain_search_list_len-- > 0) - { - o->domain_search_list[o->domain_search_list_len] = NULL; - } + o->domain_search_list_len = 0; + CLEAR(o->domain_search_list); o->disable_nbt = 0; o->dhcp_options = 0;