[meta-networking][wrynose][PATCH] openvpn: fix CVE-2026-40215
Omkar Patil <[email protected]>
| Newsgroups | org.openembedded.lists.openembedded-devel |
|---|---|
| Message-ID | <[email protected]> |
A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion Reference: [https://nvd.nist.gov/vuln/detail/CVE-2026-40215] [https://security-tracker.debian.org/tracker/CVE-2026-40215] Upstream patch: [https://github.com/OpenVPN/openvpn/commit/4a2c827c2536aa03a1d6c7cc916689a46c067187] Signed-off-by: Omkar Patil <[email protected]> --- .../openvpn/openvpn/CVE-2026-40215.patch | 59 +++++++++++++++++++ .../recipes-support/openvpn/openvpn_2.7.0.bb | 1 + 2 files changed, 60 insertions(+) create mode 100644 meta-networking/recipes-support/openvpn/openvpn/CVE-2026-40215.patch diff --git a/meta-networking/recipes-support/openvpn/openvpn/CVE-2026-40215.patch b/meta-networking/recipes-support/openvpn/openvpn/CVE-2026-40215.patch new file mode 100644 index 0000000000..e1bd0c99df --- /dev/null +++ b/meta-networking/recipes-support/openvpn/openvpn/CVE-2026-40215.patch @@ -0,0 +1,59 @@ +From 4a2c827c2536aa03a1d6c7cc916689a46c067187 Mon Sep 17 00:00:00 2001 +From: Arne Schwabe <[email protected]> +Date: Fri, 10 Apr 2026 16:59:53 +0200 +Subject: [PATCH] Ensure that buffer of freed session are not used + +In a race condition an old TLS session could still try to send a packet but +also get replaced by a new session. In this case, the buffer of the new +session is still referenced. Add the check_session_buf_not_used function +to mitigate this problem. + +Also make the check if the to_link pointer is in one of the memory +regions a bit better even though this not make a difference with the +way we use these structs. But better safe than sorry. + +A better solution to remove the TM_INITIAL state and handle reconnecting +session in their own complete tls_multi is a more involved fix that requires +a lot more refactoring. + +CVE: 2026-40215 +Reported-By: XlabAI Team of Tencent Xuanwu Lab ([email protected]) +Reported-By: Guannan Wang ([email protected] +Reported-By: Zhanpeng Liu ([email protected]) +Reported-By: Guancheng Li ([email protected]) +Signed-off-by: Arne Schwabe <[email protected]> + +Change-Id: I7c5fa2a7a2563b7a8955d386411f3ceffe5b092f +Private-URL: https://github.com/OpenVPN/openvpn-private-issues/issues/112 +Acked-by: Gert Doering <[email protected]> + +CVE: CVE-2026-40215 +Upstream-Status: Backport [https://github.com/OpenVPN/openvpn/commit/4a2c827c2536aa03a1d6c7cc916689a46c067187] + +Signed-off-by: Gert Doering <[email protected]> +(cherry picked from commit b2a15fb84d85790eeae4a2e12b431cbfd0b0302f) +Signed-off-by: Omkar Patil <[email protected]> +--- + src/openvpn/ssl.c | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/src/openvpn/ssl.c b/src/openvpn/ssl.c +index b188b4e9b32..a63d142ec46 100644 +--- a/src/openvpn/ssl.c ++++ b/src/openvpn/ssl.c +@@ -3280,6 +3280,7 @@ tls_multi_process(struct tls_multi *multi, struct buffer *to_link, + if (i == TM_ACTIVE && ks_lame->state >= S_GENERATED_KEYS + && !multi->opt.single_session) + { ++ check_session_buf_not_used(to_link, session); + move_session(multi, TM_LAME_DUCK, TM_ACTIVE, true); + } + else +@@ -3353,6 +3354,7 @@ tls_multi_process(struct tls_multi *multi, struct buffer *to_link, + */ + if (TLS_AUTHENTICATED(multi, &multi->session[TM_INITIAL].key[KS_PRIMARY])) + { ++ check_session_buf_not_used(to_link, &multi->session[TM_ACTIVE]); + move_session(multi, TM_ACTIVE, TM_INITIAL, true); + tas = tls_authentication_status(multi); + msg(D_TLS_DEBUG_LOW, diff --git a/meta-networking/recipes-support/openvpn/openvpn_2.7.0.bb b/meta-networking/recipes-support/openvpn/openvpn_2.7.0.bb index 0cbe4641cd..4e466598dc 100644 --- a/meta-networking/recipes-support/openvpn/openvpn_2.7.0.bb +++ b/meta-networking/recipes-support/openvpn/openvpn_2.7.0.bb @@ -12,6 +12,7 @@ SRC_URI = "http://swupdate.openvpn.org/community/releases/${BP}.tar.gz \ file://0001-tests-skip-test-execution-when-cross-compiling.patch \ file://openvpn \ file://run-ptest \ + file://CVE-2026-40215.patch \ " UPSTREAM_CHECK_URI = "https://openvpn.net/community-downloads" -- 2.40.0