[meta-networking][wrynose][PATCH] openvpn: fix CVE-2026-40215

Omkar Patil <[email protected]>
Newsgroups org.openembedded.lists.openembedded-devel
Message-ID <[email protected]>
A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1
through 2.7.1 allows remote attackers to potentially cause a
server crash or leak heap memory via a use-after-free triggered
during TLS session promotion

Reference:
[https://nvd.nist.gov/vuln/detail/CVE-2026-40215]
[https://security-tracker.debian.org/tracker/CVE-2026-40215]

Upstream patch:
[https://github.com/OpenVPN/openvpn/commit/4a2c827c2536aa03a1d6c7cc916689a46c067187]

Signed-off-by: Omkar Patil <[email protected]>
---
 .../openvpn/openvpn/CVE-2026-40215.patch      | 59 +++++++++++++++++++
 .../recipes-support/openvpn/openvpn_2.7.0.bb  |  1 +
 2 files changed, 60 insertions(+)
 create mode 100644 meta-networking/recipes-support/openvpn/openvpn/CVE-2026-40215.patch

diff --git a/meta-networking/recipes-support/openvpn/openvpn/CVE-2026-40215.patch b/meta-networking/recipes-support/openvpn/openvpn/CVE-2026-40215.patch
new file mode 100644
index 0000000000..e1bd0c99df
--- /dev/null
+++ b/meta-networking/recipes-support/openvpn/openvpn/CVE-2026-40215.patch
@@ -0,0 +1,59 @@
+From 4a2c827c2536aa03a1d6c7cc916689a46c067187 Mon Sep 17 00:00:00 2001
+From: Arne Schwabe <[email protected]>
+Date: Fri, 10 Apr 2026 16:59:53 +0200
+Subject: [PATCH] Ensure that buffer of freed session are not used
+
+In a race condition an old TLS session could still try to send a packet but
+also get replaced by a new session. In this case, the buffer of the new
+session is still referenced. Add the check_session_buf_not_used function
+to mitigate this problem.
+
+Also make the check if the to_link pointer is in one of the memory
+regions a bit better even though this not make a difference with the
+way we use these structs. But better safe than sorry.
+
+A better solution to remove the TM_INITIAL state and handle reconnecting
+session in their own complete tls_multi is a more involved fix that requires
+a lot more refactoring.
+
+CVE: 2026-40215
+Reported-By: XlabAI Team of Tencent Xuanwu Lab ([email protected])
+Reported-By: Guannan Wang ([email protected]
+Reported-By: Zhanpeng Liu ([email protected])
+Reported-By: Guancheng Li ([email protected])
+Signed-off-by: Arne Schwabe <[email protected]>
+
+Change-Id: I7c5fa2a7a2563b7a8955d386411f3ceffe5b092f
+Private-URL: https://github.com/OpenVPN/openvpn-private-issues/issues/112
+Acked-by: Gert Doering <[email protected]>
+
+CVE: CVE-2026-40215
+Upstream-Status: Backport [https://github.com/OpenVPN/openvpn/commit/4a2c827c2536aa03a1d6c7cc916689a46c067187]
+
+Signed-off-by: Gert Doering <[email protected]>
+(cherry picked from commit b2a15fb84d85790eeae4a2e12b431cbfd0b0302f)
+Signed-off-by: Omkar Patil <[email protected]>
+---
+ src/openvpn/ssl.c | 2 ++
+ 1 file changed, 2 insertions(+)
+
+diff --git a/src/openvpn/ssl.c b/src/openvpn/ssl.c
+index b188b4e9b32..a63d142ec46 100644
+--- a/src/openvpn/ssl.c
++++ b/src/openvpn/ssl.c
+@@ -3280,6 +3280,7 @@ tls_multi_process(struct tls_multi *multi, struct buffer *to_link,
+                 if (i == TM_ACTIVE && ks_lame->state >= S_GENERATED_KEYS
+                     && !multi->opt.single_session)
+                 {
++                    check_session_buf_not_used(to_link, session);
+                     move_session(multi, TM_LAME_DUCK, TM_ACTIVE, true);
+                 }
+                 else
+@@ -3353,6 +3354,7 @@ tls_multi_process(struct tls_multi *multi, struct buffer *to_link,
+      */
+     if (TLS_AUTHENTICATED(multi, &multi->session[TM_INITIAL].key[KS_PRIMARY]))
+     {
++        check_session_buf_not_used(to_link, &multi->session[TM_ACTIVE]);
+         move_session(multi, TM_ACTIVE, TM_INITIAL, true);
+         tas = tls_authentication_status(multi);
+         msg(D_TLS_DEBUG_LOW,
diff --git a/meta-networking/recipes-support/openvpn/openvpn_2.7.0.bb b/meta-networking/recipes-support/openvpn/openvpn_2.7.0.bb
index 0cbe4641cd..4e466598dc 100644
--- a/meta-networking/recipes-support/openvpn/openvpn_2.7.0.bb
+++ b/meta-networking/recipes-support/openvpn/openvpn_2.7.0.bb
@@ -12,6 +12,7 @@ SRC_URI = "http://swupdate.openvpn.org/community/releases/${BP}.tar.gz \
            file://0001-tests-skip-test-execution-when-cross-compiling.patch \
            file://openvpn \
            file://run-ptest \
+           file://CVE-2026-40215.patch \
           "
 
 UPSTREAM_CHECK_URI = "https://openvpn.net/community-downloads"
-- 
2.40.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.