diff mbox series

[meta-networking,wrynose] openvpn: fix CVE-2026-40215

Message ID 20260806062248.2339681-1-OmkarAbaji.Patil@windriver.com
State New
Headers show
Series [meta-networking,wrynose] openvpn: fix CVE-2026-40215 | expand

Commit Message

Omkar Patil Aug. 6, 2026, 6:22 a.m. UTC
A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1
through 2.7.1 allows remote attackers to potentially cause a
server crash or leak heap memory via a use-after-free triggered
during TLS session promotion

Reference:
[https://nvd.nist.gov/vuln/detail/CVE-2026-40215]
[https://security-tracker.debian.org/tracker/CVE-2026-40215]

Upstream patch:
[https://github.com/OpenVPN/openvpn/commit/4a2c827c2536aa03a1d6c7cc916689a46c067187]

Signed-off-by: Omkar Patil <OmkarAbaji.Patil@windriver.com>
---
 .../openvpn/openvpn/CVE-2026-40215.patch      | 59 +++++++++++++++++++
 .../recipes-support/openvpn/openvpn_2.7.0.bb  |  1 +
 2 files changed, 60 insertions(+)
 create mode 100644 meta-networking/recipes-support/openvpn/openvpn/CVE-2026-40215.patch
diff mbox series

Patch

diff --git a/meta-networking/recipes-support/openvpn/openvpn/CVE-2026-40215.patch b/meta-networking/recipes-support/openvpn/openvpn/CVE-2026-40215.patch
new file mode 100644
index 0000000000..e1bd0c99df
--- /dev/null
+++ b/meta-networking/recipes-support/openvpn/openvpn/CVE-2026-40215.patch
@@ -0,0 +1,59 @@ 
+From 4a2c827c2536aa03a1d6c7cc916689a46c067187 Mon Sep 17 00:00:00 2001
+From: Arne Schwabe <arne@rfc2549.org>
+Date: Fri, 10 Apr 2026 16:59:53 +0200
+Subject: [PATCH] Ensure that buffer of freed session are not used
+
+In a race condition an old TLS session could still try to send a packet but
+also get replaced by a new session. In this case, the buffer of the new
+session is still referenced. Add the check_session_buf_not_used function
+to mitigate this problem.
+
+Also make the check if the to_link pointer is in one of the memory
+regions a bit better even though this not make a difference with the
+way we use these structs. But better safe than sorry.
+
+A better solution to remove the TM_INITIAL state and handle reconnecting
+session in their own complete tls_multi is a more involved fix that requires
+a lot more refactoring.
+
+CVE: 2026-40215
+Reported-By: XlabAI Team of Tencent Xuanwu Lab (xlabai@tencent.com)
+Reported-By: Guannan Wang (wgnbuaa@gmail.com
+Reported-By: Zhanpeng Liu (pkugenuine@gmail.com)
+Reported-By: Guancheng Li (lgcpku@gmail.com)
+Signed-off-by: Arne Schwabe <arne@rfc2549.org>
+
+Change-Id: I7c5fa2a7a2563b7a8955d386411f3ceffe5b092f
+Private-URL: https://github.com/OpenVPN/openvpn-private-issues/issues/112
+Acked-by: Gert Doering <gert@greenie.muc.de>
+
+CVE: CVE-2026-40215
+Upstream-Status: Backport [https://github.com/OpenVPN/openvpn/commit/4a2c827c2536aa03a1d6c7cc916689a46c067187]
+
+Signed-off-by: Gert Doering <gert@greenie.muc.de>
+(cherry picked from commit b2a15fb84d85790eeae4a2e12b431cbfd0b0302f)
+Signed-off-by: Omkar Patil <OmkarAbaji.Patil@windriver.com>
+---
+ src/openvpn/ssl.c | 2 ++
+ 1 file changed, 2 insertions(+)
+
+diff --git a/src/openvpn/ssl.c b/src/openvpn/ssl.c
+index b188b4e9b32..a63d142ec46 100644
+--- a/src/openvpn/ssl.c
++++ b/src/openvpn/ssl.c
+@@ -3280,6 +3280,7 @@ tls_multi_process(struct tls_multi *multi, struct buffer *to_link,
+                 if (i == TM_ACTIVE && ks_lame->state >= S_GENERATED_KEYS
+                     && !multi->opt.single_session)
+                 {
++                    check_session_buf_not_used(to_link, session);
+                     move_session(multi, TM_LAME_DUCK, TM_ACTIVE, true);
+                 }
+                 else
+@@ -3353,6 +3354,7 @@ tls_multi_process(struct tls_multi *multi, struct buffer *to_link,
+      */
+     if (TLS_AUTHENTICATED(multi, &multi->session[TM_INITIAL].key[KS_PRIMARY]))
+     {
++        check_session_buf_not_used(to_link, &multi->session[TM_ACTIVE]);
+         move_session(multi, TM_ACTIVE, TM_INITIAL, true);
+         tas = tls_authentication_status(multi);
+         msg(D_TLS_DEBUG_LOW,
diff --git a/meta-networking/recipes-support/openvpn/openvpn_2.7.0.bb b/meta-networking/recipes-support/openvpn/openvpn_2.7.0.bb
index 0cbe4641cd..4e466598dc 100644
--- a/meta-networking/recipes-support/openvpn/openvpn_2.7.0.bb
+++ b/meta-networking/recipes-support/openvpn/openvpn_2.7.0.bb
@@ -12,6 +12,7 @@  SRC_URI = "http://swupdate.openvpn.org/community/releases/${BP}.tar.gz \
            file://0001-tests-skip-test-execution-when-cross-compiling.patch \
            file://openvpn \
            file://run-ptest \
+           file://CVE-2026-40215.patch \
           "
 
 UPSTREAM_CHECK_URI = "https://openvpn.net/community-downloads"