From patchwork Sat Sep 19 19:18:04 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Gert Doering X-Patchwork-Id: 5390 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:6446:b0:8a0:ea1f:253a with SMTP id n6csp10227243mag; Sat, 19 Sep 2026 12:18:25 -0700 (PDT) X-Forwarded-Encrypted: i=2; AKwUvBzIff0OYlS/0FDaquM9QnDr+S8WD0EF1cZh5R3TqaxU0Z2x1U7ZL1B81twb45E3cGDle3ok5KHfMPo=@openvpn.net X-Received: by 2002:a05:6808:c3ef:b0:4c2:a601:23bc with SMTP id 5614622812f47-4cb67bebe71mr8054732b6e.7.1789845505217; Sat, 19 Sep 2026 12:18:25 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1789845505; cv=none; d=google.com; s=arc-20260327; b=m76DJhUAD5eNHODoSduxaQULrw4GhyEwjVcWEaHwc0yWJBVf2p69itQtHexaCkR/Zp 7AXfuBXElqTZkDXNty/iItpyAs+VSeXT/y+N9pSGTKCOqoYhVUtX5boT64OyMnha/b6w 29euf6xAH4jagIk4/LckRVMjeju+x5VLuCcDY1X32ioEngICU73GJ9G71YbR65wDkWyJ XPTTix81RmpWOjRkE4e1MdqvVwC1CANl4lBSRVgdyw3wI7FfsjQT0sDTQmAshU9iVNpM dF3U59frKrR3aUg24RkwFXNuNrYkqJNXgBoe08iNwYRBtFPVoaUgLZQPhqFRNH28ysAZ /O4w== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature; bh=aIoaqvBWjpm5kO51rjazy3tD/ezPm3GBVKD/23fW9Gc=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=bI2D7tRgyO9SIRozoMh7LLsMgeGqariGv3XpW0S7EddAqrax30MpYuBbMUj1JSDIwg wwVHUvZO25lnL9OWof6YVlvDg3yxRCU4FNgkUxCiA7KvisHQoXenwd0F0rjXru8S0gFq UqHsaUUydX9eowMPQ8y+oeixql9PeOHkGRfAWt6eLqEljb0vDKLhRkO67y7X5zTiMEy3 58KpBz0MBzedvJF5ieJVvxi9gEkjlrQtZiE9yGxpPnEYptfjvQVGqn3bUprtpFQ0KmaA GvvHaHcErZYXIcROLsez/ZH1qeQmzI74xRQZBbnAlaLN6Ef6iE1XjZ5w/Kp0+DBpQeX3 4nGA==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=iqRQPQun; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=QIQzWI1f; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=XXdEWJSv; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 5614622812f47-4cf3fcc2b0fsi4915051b6e.129.2026.09.19.12.18.24 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Sat, 19 Sep 2026 12:18:25 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=iqRQPQun; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=QIQzWI1f; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=XXdEWJSv; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=aIoaqvBWjpm5kO51rjazy3tD/ezPm3GBVKD/23fW9Gc=; b=iqRQPQunFHFQvNN+8Qy4ypOdhV fTuoS0CUq9zX6iABwcJr9GNxVBBN0BoVhx1JcyutoRp7OX9a/ZIhaXOsG2waqRAJvmWfaN0cshisF o+h4ghMUgtUm31sBW+kUK01/Xby6RTBfhYLcJFZXflm20f/l6NhXQNFnH6qxV0AHGFKE=; Received: from [127.0.0.1] (helo=sfs-ml-1.v29.lw.sourceforge.com) by sfs-ml-1.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1x80Zr-000552-Ia; Sat, 19 Sep 2026 19:18:21 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-1.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1x80Zq-00054w-JP for openvpn-devel@lists.sourceforge.net; Sat, 19 Sep 2026 19:18:20 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=h5S82dwCx6zpx+50jAmrT8+BpA7ItGT0viqAZMQRG1E=; b=QIQzWI1f/6POpAXl57JB0GHUd0 ZX5a7d3ZjbPDoHaj5jOQjOpaIlmbMJhfa2PjZ3cHe73Rg3qZjvvv97doraj2lyj7Tw82RlZPgioP6 qDRCqvzOCm72YBLzed4WkrDUauxh2jkFGptDoi4NeXm5chq2xUBiC49rXNE3Gi98XadQ=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=h5S82dwCx6zpx+50jAmrT8+BpA7ItGT0viqAZMQRG1E=; b=XXdEWJSvZJ4oQ8L9NGc+iBkG7H MOPfhd3nMn/Ev4gW/4Z6fHoAZGv/ZrJna2iYjrp1BYnWrxLgIDA4DBIwGrVFgljW6oHAf4BKeJAZ2 DZz3KaVNyxEAiVzkyAl3b+xZD59DI1u/Bmu62yH1PDTetDxMAkAk/uRsgEDzX8vwsVXE=; Received: from [193.149.48.129] (helo=blue.greenie.muc.de) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1x80Zn-0004Fn-0D for openvpn-devel@lists.sourceforge.net; Sat, 19 Sep 2026 19:18:19 +0000 Received: from blue.greenie.muc.de (localhost [127.0.0.1]) by blue.greenie.muc.de (8.18.1/8.18.1) with ESMTP id 68JJIBHG014675 for ; Sat, 19 Sep 2026 21:18:11 +0200 Received: (from gert@localhost) by blue.greenie.muc.de (8.18.2/8.18.1/Submit) id 68JJIBvq014674 for openvpn-devel@lists.sourceforge.net; Sat, 19 Sep 2026 21:18:11 +0200 From: Gert Doering To: openvpn-devel@lists.sourceforge.net Date: Sat, 19 Sep 2026 21:18:04 +0200 Message-ID: <20260919191810.14656-1-gert@greenie.muc.de> X-Mailer: git-send-email 2.53.0 In-Reply-To: References: MIME-Version: 1.0 X-Spam-Score: 1.3 (+) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: From: Antonio Quartulli The epoch data key format is defined for AEAD ciphers only. Both places that enable it locally verify this - multi.c when picking the cipher to push and ssl_ncp.c for p2p NCP - but the pulling side im [...] Content analysis details: (1.3 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 1.3 RDNS_NONE Delivered to internal network by a host with no rDNS X-Headers-End: 1x80Zn-0004Fn-0D Subject: [Openvpn-devel] [PATCH v3] ssl: reject a pushed epoch data format tag with a non-AEAD cipher X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1872701898406932544 X-GMAIL-MSGID: 1876789040572498517 From: Antonio Quartulli The epoch data key format is defined for AEAD ciphers only. Both places that enable it locally verify this - multi.c when picking the cipher to push and ssl_ncp.c for p2p NCP - but the pulling side imports the "aead-epoch" protocol flag without validating it against the cipher that was actually negotiated. A peer pushing "protocol-flags aead-epoch" together with a non-AEAD cipher therefore makes us reach the M_FATAL in init_key_contexts() and terminate the process. This can be triggered whenever a non-AEAD cipher is part of our own --data-ciphers, which is not unusual in configurations kept compatible with old peers, e.g. data-ciphers AES-256-GCM:AES-256-CBC Validate the combination in do_deferred_options(), next to the existing data v2 check, so that the mismatch is reported as an OPTIONS ERROR and the connection is restarted. Turn the now unreachable M_FATAL in init_key_contexts() into a session error as well, so that no future code path can promote this to a process exit. Change-Id: Icc0721fd4a910110507d06b4e941e9e6dbb11e9f Signed-off-by: Antonio Quartulli Acked-by: Arne Schwabe Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1836 --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge it to master. Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1836 This mail reflects revision 3 of this Change. Acked-by according to Gerrit (reflected above): Arne Schwabe diff --git a/src/openvpn/init.c b/src/openvpn/init.c index 0236886..84de986 100644 --- a/src/openvpn/init.c +++ b/src/openvpn/init.c @@ -2711,6 +2711,18 @@ return false; } + /* The epoch data format is defined for AEAD ciphers only. A peer may push + * the tag along with a non-AEAD cipher, so this has to be checked here + * rather than trusted */ + if (epoch_data && !cipher_kt_mode_aead(c->options.ciphername)) + { + msg(D_PUSH_ERRORS, + "OPTIONS ERROR: Epoch key data format tag requires an AEAD " + "cipher, but '%s' was negotiated.", + c->options.ciphername); + return false; + } + if (found & OPT_P_PUSH_MTU) { diff --git a/src/openvpn/ssl.c b/src/openvpn/ssl.c index 4a4feaf..23c8ec8 100644 --- a/src/openvpn/ssl.c +++ b/src/openvpn/ssl.c @@ -1428,10 +1428,14 @@ { if (!cipher_kt_mode_aead(key_type->cipher)) { - msg(M_FATAL, - "AEAD cipher (currently %s) " + /* The pulled options are validated in do_deferred_options(), so + * reaching this point means a code path escaped that check. Fail + * the session instead of the whole process */ + msg(D_TLS_ERRORS, + "TLS Error: AEAD cipher (currently %s) " "required for epoch data format.", cipher_kt_name(key_type->cipher)); + return KEY_GEN_FAILED; } init_epoch_keys(ks, multi, key_type, server, key2); }