From patchwork Wed Sep 2 09:57:29 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Gert Doering X-Patchwork-Id: 5309 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:2190:b0:892:1b45:3040 with SMTP id s16csp448124mae; Wed, 2 Sep 2026 02:57:48 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+RqeoMVpsGWDxxR1HAzTeeyMP56VT5+Q1ZPWUO++FRSVt5xO7ahemDyKxPLBPtfIv50XT9lSGIiqfM4=@openvpn.net X-Received: by 2002:a05:6830:81f9:b0:7f4:c05c:2e30 with SMTP id 46e09a7af769-7f781fafcf6mr4522902a34.13.1788343068518; Wed, 02 Sep 2026 02:57:48 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1788343068; cv=none; d=google.com; s=arc-20260327; b=SyIe2acRGHRrftKyiR8JGK8a/kdfC4CB4k+SvtqnDS8Mwfd5KbAMRu9/fOFYGc9QNg 32e6KwE7SWFOfm1EzdLT1XCjzgobTbJ5rFJEuNyI7bJBQaFdaGRWy7xVWhLGxpcd0Pp/ /KrOR0UL4vFYlF4MJJ6f94JAmTUolTE+JTmXvHHNfqEuYAhWaIuQOr6bdAcNFlqFO7DZ VJVUzVn7THtWoft9yM+o8qGBpIV4V8HQlW6L9WcpZh7yisRKdVwCz5HIOX5jU7NThzJh MnTh/jKF+lVsv1tH8VXVRpfIuBApgIDwGfphsi3QcAbLWO8z4AC33EReshcPu4v8VCes XfZQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature; bh=+7UDN2ufgqRxa4WOH0waCoZ1f8SeYXikwfFxk7sBOm4=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=kMZpGnUHWm9t8chXTMOx1PtGsEPEJ54zyIyQAX9YaO083kDK+fLh4trcTf+3sVfsl/ GgjgC16Drw8MnUnpRkz4aSOE7gk11Oy0qpCiMEFFt5dCQF/CGw3pyaWEEc1kSmZ5ENVd LOe7yWG1/h0SZjz1lU5QU5mk2qNQCDjVChPWHWo2eFHsYSr2kzmHWGOYkYfQmObwOwkR 5gLji5nfYSbOZcUa9aBBSfHGZ0TOIKE6njJxWtbHxYwjcgU9b3WpsBibPOkPpLNDaHgJ OwbBLCXRHbnr2eABc93rI2MjjT9QrtjHLmqwDz1/vQ/xCGI/eLGwA1pbeyWYfFxW8scG qEBg==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=e2oZAqxK; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=nO55PCOl; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=ZfSn+vbb; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 46e09a7af769-7f75121afc7si3136153a34.142.2026.09.02.02.57.48 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 02 Sep 2026 02:57:48 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=e2oZAqxK; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=nO55PCOl; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=ZfSn+vbb; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=+7UDN2ufgqRxa4WOH0waCoZ1f8SeYXikwfFxk7sBOm4=; b=e2oZAqxKb9fXUWq7sSXh3JvCfh MChJK1AtEd/j5TfoeY/6mNe+/ke87bKjnPlnAgCMRAlpgQB16JhgSqxtB68hOW8cxt2pSn3Tbp74h KxO6ja/+FRAsCf8TBBAROEZ3U42aW7RYcsFfUMx7AddykZHBVF3aPPDvpvBopaQwxdW8=; Received: from [127.0.0.1] (helo=sfs-ml-1.v29.lw.sourceforge.com) by sfs-ml-1.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1x1hj1-0003em-QR; Wed, 02 Sep 2026 09:57:45 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-1.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1x1hiz-0003ed-V0 for openvpn-devel@lists.sourceforge.net; Wed, 02 Sep 2026 09:57:43 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=a/aOQ5s91BcHBgpbr8W2Wh1agFFKnEu5S9qA6441gQA=; b=nO55PCOlKhE/in+nUAb+/vA/u1 Jxo2gegzOVK6fR3XIXVxdqrqaMaIWMK7snYStliRjs10u2P6hxiH8x5H6rqSoY5KKhilK08t3xccJ Nf75qzXffbEZBrVlct51/t0o7OODKEJlWha+UGcU5dykydex0rn3zSmkTTnMTm8idRqA=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=a/aOQ5s91BcHBgpbr8W2Wh1agFFKnEu5S9qA6441gQA=; b=ZfSn+vbbSPKB97lm8d31NhAQek oo48K2SsVYRWqwCCxwg/fTs3gthLuE65YKQE07qpKYZ5LEW9mRckkmF3n2SBW7a6Pu0bUWwLquLuI fuC/nJpbIrujmFfGhEhVmvp7b1qDrEaV0dhv8/NXNmSmVzZGqKOGFm/yNGYMuPp2ZT2Q=; Received: from [193.149.48.129] (helo=blue.greenie.muc.de) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1x1hiv-00082a-W0 for openvpn-devel@lists.sourceforge.net; Wed, 02 Sep 2026 09:57:43 +0000 Received: from blue.greenie.muc.de (localhost [127.0.0.1]) by blue.greenie.muc.de (8.18.1/8.18.1) with ESMTP id 6829vZIQ026870 for ; Wed, 2 Sep 2026 11:57:35 +0200 Received: (from gert@localhost) by blue.greenie.muc.de (8.18.2/8.18.1/Submit) id 6829vZ0r026869 for openvpn-devel@lists.sourceforge.net; Wed, 2 Sep 2026 11:57:35 +0200 From: Gert Doering To: openvpn-devel@lists.sourceforge.net Date: Wed, 2 Sep 2026 11:57:29 +0200 Message-ID: <20260902095734.26857-1-gert@greenie.muc.de> X-Mailer: git-send-email 2.53.0 In-Reply-To: References: MIME-Version: 1.0 X-Spam-Score: 1.3 (+) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: From: Heiko Hund Provide a application name to CreateProcess(), so that it doesn't try to locate an executable - somewhere. Instead construct the full path to netsh.exe in the system dir and pass that to the function [...] Content analysis details: (1.3 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 1.3 RDNS_NONE Delivered to internal network by a host with no rDNS X-Headers-End: 1x1hiv-00082a-W0 Subject: [Openvpn-devel] [PATCH v1] tapctl: prevent binary planting with netsh X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1875213621413430860 X-GMAIL-MSGID: 1875213621413430860 From: Heiko Hund Provide a application name to CreateProcess(), so that it doesn't try to locate an executable - somewhere. Instead construct the full path to netsh.exe in the system dir and pass that to the function instead of NULL. Discovered and reported by BreachX Zero Day Labs, using Typhon AI Mil v2. Contributing Researcher: Vivek Parikh. Reported-by: Vivek Parikh Tested-by: Vivek Parikh Github: OpenVPN/openvpn-private-issues#164 CVE: 2026-84226 Change-Id: I70282985a7e8e46add92b2277674cbca6bce39c1 Signed-off-by: Heiko Hund Acked-by: Razvan Cojocaru Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1890 --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge it to master. Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1890 This mail reflects revision 1 of this Change. Acked-by according to Gerrit (reflected above): Razvan Cojocaru diff --git a/src/tapctl/tap.c b/src/tapctl/tap.c index 1d94988..769df6c 100644 --- a/src/tapctl/tap.c +++ b/src/tapctl/tap.c @@ -921,32 +921,38 @@ bEnable ? enable_device : disable_device, pbRebootRequired); } -/* stripped version of ExecCommand in interactive.c */ static DWORD -ExecCommand(const WCHAR *cmdline) +ExecNetsh(PWSTR cmdline) { DWORD exit_code; STARTUPINFOW si; PROCESS_INFORMATION pi; DWORD proc_flags = CREATE_NO_WINDOW | CREATE_UNICODE_ENVIRONMENT; - WCHAR *cmdline_dup = NULL; ZeroMemory(&si, sizeof(si)); ZeroMemory(&pi, sizeof(pi)); - si.cb = sizeof(si); - /* CreateProcess needs a modifiable cmdline: make a copy */ - cmdline_dup = _wcsdup(cmdline); - if (cmdline_dup - && CreateProcessW(NULL, cmdline_dup, NULL, NULL, FALSE, proc_flags, NULL, NULL, &si, &pi)) + WCHAR appName[MAX_PATH]; + WCHAR netsh_exe[] = L"\\netsh.exe"; + UINT sysdir_len = GetSystemDirectoryW(appName, _countof(appName)); + if (sysdir_len == 0) + { + wcscpy_s(appName, _countof(appName), L"C:\\Windows\\system32"); + } + else if (sysdir_len + _countof(netsh_exe) > _countof(appName)) + { + return ERROR_INSUFFICIENT_BUFFER; + } + wcscat_s(appName, _countof(appName), netsh_exe); + + if (CreateProcessW(appName, cmdline, NULL, NULL, FALSE, proc_flags, NULL, NULL, &si, &pi)) { WaitForSingleObject(pi.hProcess, INFINITE); if (!GetExitCodeProcess(pi.hProcess, &exit_code)) { exit_code = GetLastError(); } - CloseHandle(pi.hProcess); CloseHandle(pi.hThread); } @@ -955,7 +961,6 @@ exit_code = GetLastError(); } - free(cmdline_dup); return exit_code; } @@ -1013,7 +1018,7 @@ free(szOldName); - dwResult = ExecCommand(szCmdLine); + dwResult = ExecNetsh(szCmdLine); free(szCmdLine); if (dwResult != ERROR_SUCCESS)