From patchwork Sun Aug 30 18:21:27 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Gert Doering X-Patchwork-Id: 5300 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:c317:b0:87d:ab56:3700 with SMTP id jk23csp2331177mab; Sun, 30 Aug 2026 11:21:49 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+RpLTZhLRxEtrezB8qbf7q0Wcwve3vUy2EA9Kdp+pA6fWbwRWQlGUSutFQbCdGRpqT0Mv7z5fR1/q7I=@openvpn.net X-Received: by 2002:a05:6808:514a:b0:4b3:1a95:42d8 with SMTP id 5614622812f47-4b397fa355fmr24606323b6e.8.1788114108925; Sun, 30 Aug 2026 11:21:48 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1788114108; cv=none; d=google.com; s=arc-20260327; b=B4ZdEJFn6rXgQypOip+OG6mmaawWr0ryqb0q0MeS2PFRu7FKs7hP5xf+2nK/6sL4y5 F80+ixfVQkMfRnsLm32+m7kE1mq9wVEjQiHWaja7i1Do9PcJ74vDeLJQa14uyBVpBqtx hqZp45mrTJPN0O+shWAm5kdTZABI/1nFupNQr8FhTlGGwZ+30aGe2gHMmgkEzJteAeFK uPk95tHtv9C1S0kZUHvbB6fvoFShexFDDzlmG2YsvJZRVwi0SgWLEt2pbRM+9b3I0dWT wg0cJj3ouTOb34Qm/VlHFvTI4ejXB5/bVVb5JO77bgzmlKzzERdMdBAhFPDlAQruQ4Uf 27Qg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature; bh=t/xk8RfJqAKoRHIteztoszF7JCxp7rTDBRg67+n0LLA=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=ITWt8TqHv2sq2aEMExXIJlmUuJafj+MOd9MLSbl0U4YSvVseY3Y1iZK/pow7lJvaDz YRXY5hKg2uzJEdSSBdoXN1wzBHMkqoLs2zOOUhV9+XazMNAod5NObd7YTxthuQGgI96l PaqZaPn5Tb5d3DHc8JyHmZEVU9ps+7817Hfjn0dlHsGYKgsjdrRn5Rdl/W0lskrGebvN +3XKXltTPJb7sTn5qQP2/KAjWB3bKjG/PpjNpO0t/VHi86xl2N9HLOrQxDVG2yLSRgV9 Df2mdwQRiZtZiC5KyMOU+rcH7bJTdATFP1FNhNDzOod75TZkBjPJYLCxJCxIAY65L5Af hehQ==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=IDQuO0V7; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=SpxxjiTp; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=l7qyEwno; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 5614622812f47-4b3a16c3e7dsi12432117b6e.36.2026.08.30.11.21.48 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Sun, 30 Aug 2026 11:21:48 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=IDQuO0V7; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=SpxxjiTp; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=l7qyEwno; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=t/xk8RfJqAKoRHIteztoszF7JCxp7rTDBRg67+n0LLA=; b=IDQuO0V7PusYPoXaihhz3umadN 2BfONjePflaKZoWKvE82dIjvhwubhFIz7ZqOcEnwJm8Le/Mcl1zCCbbQ1yQUH9bEJQ1WqQB0GqJB3 sKZW6Z42pcrD1kJldEXxVE1OK3xDPw38xtCZnkK5vk29XsXqA+RM3lyHzdVjli8xyh+c=; Received: from [127.0.0.1] (helo=sfs-ml-4.v29.lw.sourceforge.com) by sfs-ml-4.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1x0kA4-0006Ox-Ja; Sun, 30 Aug 2026 18:21:44 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-4.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1x0kA2-0006Oq-TB for openvpn-devel@lists.sourceforge.net; Sun, 30 Aug 2026 18:21:42 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=AJVkQbYirw5Bz2LYrRLVUcNjDlivlFTkwAskazo1ezk=; b=SpxxjiTpHYEJFlsvLk7EYZhWX9 nIGivLIMPVbszWWy3xgTViQfdKYXJcK3Rp97/R7RwUetNqVAO7XwKc/fYb+2tmvLHrsa3XsBWq8Xe zcRXR67Cq3ZK9PD9f+CV8WQbnciLgso2i0oY3hKJtc4X3U/8i/daDso7vhMjlIv8ZGu4=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=AJVkQbYirw5Bz2LYrRLVUcNjDlivlFTkwAskazo1ezk=; b=l7qyEwno8SkC2biHT29WW1aulC 8WSWTDdwS2yfF68yJFdIIER3QojvttwWZNJJVqTw7pgWsMHz8gjlL7b3NYRvwFIsUsvMOjjizQ7rQ 7Qhy5v3iWc1z89CH4Ga+T2KyniJdafKpEOGDCbyeqh81odN7M+8MWdNpiwGu/570li+w=; Received: from [193.149.48.129] (helo=blue.greenie.muc.de) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1x0kA1-0002lH-QJ for openvpn-devel@lists.sourceforge.net; Sun, 30 Aug 2026 18:21:42 +0000 Received: from blue.greenie.muc.de (localhost [127.0.0.1]) by blue.greenie.muc.de (8.18.1/8.18.1) with ESMTP id 67UILYHG032284 for ; Sun, 30 Aug 2026 20:21:34 +0200 Received: (from gert@localhost) by blue.greenie.muc.de (8.18.2/8.18.1/Submit) id 67UILYen032283 for openvpn-devel@lists.sourceforge.net; Sun, 30 Aug 2026 20:21:34 +0200 From: Gert Doering To: openvpn-devel@lists.sourceforge.net Date: Sun, 30 Aug 2026 20:21:27 +0200 Message-ID: <20260830182134.32251-1-gert@greenie.muc.de> X-Mailer: git-send-email 2.53.0 In-Reply-To: References: MIME-Version: 1.0 X-Spam-Score: 1.3 (+) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-1.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: From: Heiko Hund If the config_dir value in the registry has no trailing backslash the check doesn't actually guarantee that a file is located within config_dir, because a sibling dir with the same prefix, e.g. 'confi [...] Content analysis details: (1.3 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 1.3 RDNS_NONE Delivered to internal network by a host with no rDNS X-Headers-End: 1x0kA1-0002lH-QJ Subject: [Openvpn-devel] [PATCH v1] openvpnserv: detect sibling dirs in CheckConfigPath X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1874973539614350762 X-GMAIL-MSGID: 1874973539614350762 From: Heiko Hund If the config_dir value in the registry has no trailing backslash the check doesn't actually guarantee that a file is located within config_dir, because a sibling dir with the same prefix, e.g. 'config' and 'config-evil' will match and produce a positive verdict. By also checking that there is a path separator after config_dir prevents this attack. Reported-By: Harshit Varu Tested-By: Harshit Varu CVE: 2026-81830 Github: OpenVPN/openvpn-private-issues#166 Change-Id: Ica5d43989b441d4377a3908f811a2953b7a9d45a Signed-off-by: Heiko Hund Acked-by: Razvan Cojocaru Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1883 --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge it to release/2.6. Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1883 This mail reflects revision 1 of this Change. Acked-by according to Gerrit (reflected above): Razvan Cojocaru diff --git a/src/openvpnserv/validate.c b/src/openvpnserv/validate.c index 770a7a0..b0fb6b85 100644 --- a/src/openvpnserv/validate.c +++ b/src/openvpnserv/validate.c @@ -56,7 +56,9 @@ /* * Check workdir\fname is inside config_dir - * The logic here is simple: we may reject some valid paths if ..\ is in any of the strings + * The logic here is simple: + * we may reject some valid paths if ".." is in the filename + * or if there's no "\" after the config directory */ static BOOL CheckConfigPath(const WCHAR *workdir, const WCHAR *fname, const settings_t *s) @@ -82,9 +84,18 @@ } config_dir = s->config_dir; + size_t config_dir_len = wcslen(config_dir); - if (wcsncmp(config_dir, config_file, wcslen(config_dir)) == 0 - && wcsstr(config_file + wcslen(config_dir), L"..") == NULL) + /* check for a path separator after config_dir */ + if (config_dir_len && config_dir_len < wcslen(config_file) + && config_dir[config_dir_len - 1] != L'\\' + && config_file[config_dir_len] != L'\\') + { + return FALSE; + } + + if (wcsncmp(config_dir, config_file, config_dir_len) == 0 + && wcsstr(config_file + config_dir_len, L"..") == NULL) { return TRUE; }