)]}'
{"id":"openvpn~1713","triplet_id":"openvpn~release%2F2.7~Iac54e6772b2c26a09227fd638d24d6e2aa35cec6","project":"openvpn","branch":"release/2.7","attention_set":{},"removed_from_attention_set":{"1000003":{"account":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"last_update":"2026-06-18 12:21:08.000000000","reason":"removed on reply"},"1000002":{"account":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"last_update":"2026-06-20 10:28:54.000000000","reason":"Change was submitted"}},"hashtags":[],"change_id":"Iac54e6772b2c26a09227fd638d24d6e2aa35cec6","subject":"Fix 1-byte buffer overrun on NTLMv2 proxy responses.","status":"MERGED","created":"2026-06-17 17:17:58.000000000","updated":"2026-06-20 10:28:54.000000000","submitted":"2026-06-20 10:28:54.000000000","submitter":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"total_comment_count":4,"unresolved_comment_count":3,"has_review_started":true,"submission_id":"1713","meta_rev_id":"98ca706f7c18cd7e02ed78525b3a4467e419af86","_number":1713,"virtual_id_number":1713,"owner":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"actions":{},"labels":{"Code-Review":{"all":[{"value":0,"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},{"value":0,"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"}],"values":{"-2":"This shall not be submitted","-1":"I would prefer this is not submitted as is"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me, approved"},"description":"","default_value":0}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"}],"CC":[{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-06-17 17:17:58.000000000","updated_by":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"reviewer":{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"},"state":"CC"},{"updated":"2026-06-17 17:17:58.000000000","updated_by":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"reviewer":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"state":"REVIEWER"}],"messages":[{"id":"d031952d32bde20aaa68e5cc7cb4ead0ac2e88e8","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"date":"2026-06-17 17:17:58.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"25dc131422b37463f1131f03463fbd8fb52209b2","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"date":"2026-06-17 17:47:59.000000000","message":"Uploaded patch set 2: Commit message was updated.","accounts_in_message":[],"_revision_number":2},{"id":"3ed6c4c9485e4b190675c74b1d59ecfe1ed75c10","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-06-18 12:21:08.000000000","message":"Patch Set 2: Code-Review+2\n\n(3 comments)","accounts_in_message":[],"_revision_number":2},{"id":"b35707445dabc124d74c3af4010e0e0f385c34e0","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-06-18 12:21:36.000000000","message":"Patch Set 2:\n\n(1 comment)","accounts_in_message":[],"_revision_number":2},{"id":"98ca706f7c18cd7e02ed78525b3a4467e419af86","tag":"autogenerated:gerrit:merged","author":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"date":"2026-06-20 10:28:54.000000000","message":"Change has been successfully pushed.","accounts_in_message":[],"_revision_number":3}],"current_revision_number":3,"current_revision":"04309bfe0313c09edd02c29945893b9d7e2ca920","revisions":{"5582fc46e59592828105d11ac11e1ba1a3bfba14":{"kind":"REWORK","_number":1,"created":"2026-06-17 17:17:58.000000000","uploader":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"ref":"refs/changes/13/1713/1","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/13/1713/1","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/13/1713/1 \u0026\u0026 git checkout -b change-1713 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/13/1713/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/13/1713/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/13/1713/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/13/1713/1","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/13/1713/1 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"ae5083017d70c695813cd7974d1fabbf0eb7307a","subject":"Multisocket: use event engine rwflags for UDP I/O"}],"author":{"name":"Gert Doering","email":"gert@greenie.muc.de","date":"2026-06-17 17:12:24.000000000","tz":120},"committer":{"name":"Gert Doering","email":"gert@greenie.muc.de","date":"2026-06-17 17:12:24.000000000","tz":120},"subject":"Fix 1-byte buffer overrun on NTLMv2 proxy responses.","message":"Fix 1-byte buffer overrun on NTLMv2 proxy responses.\n\nAn attacker controlling an HTTP proxy (or performing MITM on the\nplaintext pre-TLS proxy connection) can trigger a single 0-byte\noverrun to a buffer on the stack by sending a crafted NTLM Type\n2 challenge response.\n\nThe effects of this depend on memory layout, but could possibly lead\nto a crashing OpenVPN client.\n\nReported-by: Tristan Madani (@TristanInSec)\nCVE: 2026-11771\n\nChange-Id: Iac54e6772b2c26a09227fd638d24d6e2aa35cec6\nSigned-off-by: Gert Doering \u003cgert@greenie.muc.de\u003e\n"},"branch":"refs/heads/release/2.7"},"57bce06563118f9853c6002ae87653f3ec125f15":{"kind":"NO_CODE_CHANGE","_number":2,"created":"2026-06-17 17:47:59.000000000","uploader":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"ref":"refs/changes/13/1713/2","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/13/1713/2","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/13/1713/2 \u0026\u0026 git checkout -b change-1713 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/13/1713/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/13/1713/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/13/1713/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/13/1713/2","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/13/1713/2 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"ae5083017d70c695813cd7974d1fabbf0eb7307a","subject":"Multisocket: use event engine rwflags for UDP I/O"}],"author":{"name":"Gert Doering","email":"gert@greenie.muc.de","date":"2026-06-17 17:12:24.000000000","tz":120},"committer":{"name":"Gert Doering","email":"gert@greenie.muc.de","date":"2026-06-17 17:47:06.000000000","tz":120},"subject":"Fix 1-byte buffer overrun on NTLMv2 proxy responses.","message":"Fix 1-byte buffer overrun on NTLMv2 proxy responses.\n\nAn attacker controlling an HTTP proxy (or performing MITM on the\nplaintext pre-TLS proxy connection) can trigger a single 0-byte\noverrun to a buffer on the stack by sending a crafted NTLM Type\n2 challenge response.\n\nThe effects of this depend on memory layout, but could possibly lead\nto a crashing OpenVPN client.\n\nReported-by: Tristan Madani (@TristanInSec)\nCVE: 2026-11771\nGithub: OpenVPN/openvpn-private-issues#116\n\nChange-Id: Iac54e6772b2c26a09227fd638d24d6e2aa35cec6\nSigned-off-by: Gert Doering \u003cgert@greenie.muc.de\u003e\n"},"branch":"refs/heads/release/2.7"},"04309bfe0313c09edd02c29945893b9d7e2ca920":{"kind":"TRIVIAL_REBASE_WITH_MESSAGE_UPDATE","_number":3,"created":"2026-06-20 10:28:54.000000000","uploader":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"ref":"refs/changes/13/1713/3","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/13/1713/3","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/13/1713/3 \u0026\u0026 git checkout -b change-1713 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/13/1713/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/13/1713/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/13/1713/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/13/1713/3","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/13/1713/3 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"7f1d68ae651b0dece0044b19376bf8ed8213e764","subject":"dns: Fix memory leak in dns_server_addr_parse"}],"author":{"name":"Gert Doering","email":"gert@greenie.muc.de","date":"2026-06-18 12:37:24.000000000","tz":120},"committer":{"name":"Gert Doering","email":"gert@greenie.muc.de","date":"2026-06-20 10:18:06.000000000","tz":120},"subject":"Fix 1-byte buffer overrun on NTLMv2 proxy responses.","message":"Fix 1-byte buffer overrun on NTLMv2 proxy responses.\n\nAn attacker controlling an HTTP proxy (or performing MITM on the\nplaintext pre-TLS proxy connection) can trigger a single 0-byte\noverrun to a buffer on the stack by sending a crafted NTLM Type\n2 challenge response.\n\nThe effects of this depend on memory layout, but could possibly lead\nto a crashing OpenVPN client.\n\nReported-by: Tristan Madani (@TristanInSec)\nCVE: 2026-11771\nGithub: OpenVPN/openvpn-private-issues#116\n\nChange-Id: Iac54e6772b2c26a09227fd638d24d6e2aa35cec6\nSigned-off-by: Gert Doering \u003cgert@greenie.muc.de\u003e\nAcked-by: Arne Schwabe \u003carne-openvpn@rfc2549.org\u003e\nGerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1713\nMessage-Id: \u003c20260618123729.18337-1-gert@greenie.muc.de\u003e\nURL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg37218.html\nSigned-off-by: Gert Doering \u003cgert@greenie.muc.de\u003e\n"},"branch":"refs/heads/release/2.7"}},"requirements":[],"submit_records":[],"submit_requirements":[]}
