OpenVPN is an open source VPN daemon http://community.openvpn.net
  • C 94.3%
  • Shell 2.1%
  • M4 1.4%
  • CMake 1.1%
  • Makefile 0.8%
  • Other 0.3%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Cole Munz aa12dd64b7 options: fix unsigned underflow when clearing domain_search_list
remove_option() and update_option() clear the domain search list with

    while (o->domain_search_list_len-- > 0)

domain_search_list_len is unsigned, and the post-decrement runs on the
final test too. When the length reaches 0 the condition is false but
the decrement has already wrapped it to UINT_MAX, so the field is left
corrupted. The next reset then does

    o->domain_search_list[UINT_MAX] = NULL

and walks far out of bounds, writing NULL through each slot. A server
can drive this reset path against a client with PUSH_UPDATE, so on
Windows and Android this is a remotely reachable out-of-bounds write.

v2:
  Change to the semantics used for all the other lists there - set
  length to 0 and clear the list with CLEAR().

Change-Id: I3724236d4acc3d05d786274d6baf34a21c570594
Signed-off-by: Cole Munz <Munzzyy1@proton.me>
Acked-by: Razvan Cojocaru <razvanc@mailbox.org>
Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1914
Github: OpenVPN/openvpn-private-issues#178
CVE: 2026-88964
Message-Id: <20260913132322.2283-1-gert@greenie.muc.de>
URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg39157.html
Signed-off-by: Gert Doering <gert@greenie.muc.de>
2026-09-14 08:31:20 +02:00
.github mbedtls: Work-around bug in mbedtls 4.1.0 and 4.2.0 2026-08-30 18:17:45 +02:00
contrib Fix pkgcs11 vcpkg port installing debug files on release builds 2026-04-28 15:54:16 +02:00
debug build: standard directory layout 2012-03-22 22:07:08 +01:00
dev-tools Remove various useless assignments 2026-09-13 12:05:18 +02:00
distro dns-scripts: Fix dnssec values in comments and Copyright statement format 2026-04-30 15:19:34 +02:00
doc multi: don't let stale-routes-check delete permanent routes 2026-08-26 09:31:50 +02:00
include win: Fix nrpt_dnssec flag handling 2026-04-05 16:28:20 +02:00
m4 m4: Add ax_code_coverage 2026-08-18 14:27:49 +02:00
sample Remove instances of constVariable/constVariablePointer cppcheck warnings 2026-08-25 09:48:40 +02:00
src options: fix unsigned underflow when clearing domain_search_list 2026-09-14 08:31:20 +02:00
tests Remove various useless assignments 2026-09-13 12:05:18 +02:00
.clang-format .clang-format: Convert deprecated setting KeepEmptyLinesAtTheStartOfBlocks 2026-08-20 12:58:14 +02:00
.git-blame-ignore-revs Add clang-format reformat commit to .git-blame-ignore-revs 2025-08-05 17:07:05 +02:00
.gitattributes cleanup: add .gitattributes to control eol style explicitly 2012-04-26 20:54:26 +02:00
.gitignore dns: apply settings via script on unixoid systems 2025-05-14 18:17:51 +02:00
.mailmap Update .mailmap to unify and clean up odd names and e-mail addresses 2016-10-18 13:46:04 +02:00
.pre-commit-config.yaml Update the clang-format reference version to 21.1.8 2026-02-10 16:29:04 +01:00
.svncommitters Added mapping files from SVN commit ID to more descriptive commit IDs. 2010-10-21 11:31:26 +02:00
AUTHORS This is the start of the BETA21 branch. 2005-09-26 05:28:27 +00:00
ChangeLog start release/2.8 development cycle 2026-02-13 13:11:33 +01:00
Changes.md Convert Changes.rst to Markdown 2026-09-07 20:12:32 +02:00
CMakeLists.txt Move mocks from test_push_update_msg into its own compile unit 2026-08-28 12:24:43 +02:00
CMakePresets.json Add building/testing with msbuild and the clang compiler 2024-12-27 12:30:55 +01:00
CODE_CHECKLIST.md Start a new document CODE_CHECKLIST 2026-08-17 18:57:11 +02:00
compat.m4 Update GPL header in all source files to current recommended version 2025-08-03 16:55:47 +02:00
config.h.cmake.in Remove --with-mem-check=dmalloc 2026-08-09 10:32:15 +02:00
configure.ac Remove --with-mem-check=dmalloc 2026-08-09 10:32:15 +02:00
CONTRIBUTING.rst CONTRIBUTING: Update outdated/obsolete information 2025-10-13 18:10:25 +02:00
COPYING Update Copyright statements to 2026 2026-01-08 10:59:57 +01:00
COPYRIGHT.GPL Update text of GPL to latest version from FSF 2025-08-03 16:43:58 +02:00
forked-test-driver forked-test-driver: Show test output always 2024-04-02 17:20:48 +02:00
INSTALL Drop support for OpenSSL 1.1.0 2026-07-30 19:34:58 +02:00
ltrc.inc cmake: symlink whole build dir not just .json file 2024-01-17 15:01:54 +01:00
Makefile.am run-cppcheck.sh: Make it more configurable 2026-09-08 09:31:36 +02:00
NEWS This is the start of the BETA21 branch. 2005-09-26 05:28:27 +00:00
PORTS Update Copyright statements to 2026 2026-01-08 10:59:57 +01:00
README Fix copyright line in README 2026-04-21 08:17:48 +02:00
README.awslc Add compatibility to build OpenVPN with AWS-LC. 2025-01-29 17:11:19 +01:00
README.cmake.md README.cmake.md: Document minimum required CMake version for --preset 2024-02-01 20:26:45 +01:00
README.dco.md README.dco: update Linux instructions 2025-07-16 16:16:35 +02:00
README.ec Implement tls-groups option to specify eliptic curves/groups 2020-07-21 22:33:58 +02:00
README.mbedtls Add support for Mbed TLS 4 2026-01-24 18:49:44 +01:00
README.wolfssl Add a section about wolfSSL GPLv3 and point out missing TLS PRF support 2025-12-04 14:59:08 +01:00
renovate.json renovate: Fix typo in regex manager 2026-06-10 19:08:52 +02:00
version.m4 start release/2.8 development cycle 2026-02-13 13:11:33 +01:00

OpenVPN -- A Secure tunneling daemon

Copyright (C) 2002-2026 OpenVPN Inc. This program is free software;
you can redistribute it and/or modify
it under the terms of the GNU General Public License version 2
as published by the Free Software Foundation.

*************************************************************************

To get the latest release of OpenVPN, go to:

	https://openvpn.net/community-downloads/

To Build and Install,

	tar -zxf openvpn-<version>.tar.gz
	cd openvpn-<version>
	./configure
	make
	make install

or see the file INSTALL for more info.

For information on how to build OpenVPN on/for Windows with MinGW
or MSVC see README.cmake.md.

*************************************************************************

For detailed information on OpenVPN, including examples, see the man page
  http://openvpn.net/man.html

For a sample VPN configuration, see
  http://openvpn.net/howto.html

To report an issue, see
  https://github.com/OpenVPN/openvpn/issues/new

For a description of OpenVPN's underlying protocol,
  see the file ssl.h included in the source distribution.

*************************************************************************

Other Files & Directories:

* configure.ac -- script to rebuild our configure
  script and makefile.

* sample/sample-scripts/verify-cn

  A sample perl script which can be used with OpenVPN's
  --tls-verify option to provide a customized authentication
  test on embedded X509 certificate fields.

* sample/sample-keys/

  Sample RSA keys and certificates.  DON'T USE THESE FILES
  FOR ANYTHING OTHER THAN TESTING BECAUSE THEY ARE TOTALLY INSECURE.

* sample/sample-config-files/

  A collection of OpenVPN config files and scripts from
  the HOWTO at http://openvpn.net/howto.html

*************************************************************************

Note that easy-rsa and tap-windows are now maintained in their own subprojects.
Their source code is available here:

  https://github.com/OpenVPN/easy-rsa
  https://github.com/OpenVPN/tap-windows6

Community-provided Windows installers (MSI) and Debian packages are built from

  https://github.com/OpenVPN/openvpn-build

See the INSTALL file for usage information.