)]}'
{"id":"openvpn~1801","triplet_id":"openvpn~master~Ic183f1f1f90561454b7b1128c95255368427cc4a","project":"openvpn","branch":"master","attention_set":{},"removed_from_attention_set":{"1000003":{"account":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"last_update":"2026-07-22 16:19:16.000000000","reason":"Change was submitted"},"1000001":{"account":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"last_update":"2026-07-22 15:22:55.000000000","reason":"\u003cGERRIT_ACCOUNT_1000001\u003e replied on the change","reason_account":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."}},"1000030":{"account":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"last_update":"2026-07-22 15:20:17.000000000","reason":"\u003cGERRIT_ACCOUNT_1000030\u003e replied on the change","reason_account":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"}}},"hashtags":[],"change_id":"Ic183f1f1f90561454b7b1128c95255368427cc4a","subject":"Make --x509-username-field work with Mbed TLS","status":"MERGED","created":"2026-07-22 12:52:52.000000000","updated":"2026-07-22 16:19:16.000000000","submitted":"2026-07-22 16:19:16.000000000","submitter":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"total_comment_count":7,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"1801","meta_rev_id":"1453e89886678dd6bcc62252e4a0476baa1b4a64","_number":1801,"virtual_id_number":1801,"owner":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"actions":{},"labels":{"Code-Review":{"all":[{"value":0,"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},{"value":0,"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."}],"values":{"-2":"This shall not be submitted","-1":"I would prefer this is not submitted as is"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me, approved"},"description":"","default_value":0}},"removable_reviewers":[{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"}],"reviewers":{"REVIEWER":[{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"}],"CC":[{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-07-22 12:52:52.000000000","updated_by":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"reviewer":{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"},"state":"CC"},{"updated":"2026-07-22 12:52:52.000000000","updated_by":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"reviewer":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"state":"REVIEWER"},{"updated":"2026-07-22 13:29:05.000000000","updated_by":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"reviewer":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"state":"REVIEWER"}],"messages":[{"id":"ba1e6c3275109ae626e8c1e36777e810d6c267cd","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"date":"2026-07-22 12:52:52.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"44b7aea13ca8dbd447dd002a161778fe0b05bab4","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"date":"2026-07-22 13:15:52.000000000","message":"Uploaded patch set 2.","accounts_in_message":[],"_revision_number":2},{"id":"301a0a4a98cb5f5e451eda7e84678e1e45b9c3a2","author":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"date":"2026-07-22 13:29:05.000000000","message":"Patch Set 2: Code-Review-1\n\n(2 comments)","accounts_in_message":[],"_revision_number":2},{"id":"32c7f22205f173e02750f3eba36e8cbb8cf5d649","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"date":"2026-07-22 15:17:18.000000000","message":"Uploaded patch set 3.\n\nOutdated Votes:\n* Code-Review-1 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR is:MIN\")\n","accounts_in_message":[],"_revision_number":3},{"id":"beae26f594bf27a77672b79febf54944f0dbaf67","author":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"date":"2026-07-22 15:20:17.000000000","message":"Patch Set 3:\n\n(2 comments)","accounts_in_message":[],"_revision_number":3},{"id":"acfa86132d152189e0d66e8e2dc3e534a4822b0e","author":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"date":"2026-07-22 15:22:55.000000000","message":"Patch Set 3: Code-Review+2\n\n(3 comments)","accounts_in_message":[],"_revision_number":3},{"id":"1453e89886678dd6bcc62252e4a0476baa1b4a64","tag":"autogenerated:gerrit:merged","author":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"date":"2026-07-22 16:19:16.000000000","message":"Change has been successfully pushed.","accounts_in_message":[],"_revision_number":4}],"current_revision_number":4,"current_revision":"124ec07732bccc1fced2d8d37c71b761daf75f4f","revisions":{"e38dfb687235974d7a42c635e60282191267ab27":{"kind":"REWORK","_number":1,"created":"2026-07-22 12:52:52.000000000","uploader":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"ref":"refs/changes/01/1801/1","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/01/1801/1","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/01/1801/1 \u0026\u0026 git checkout -b change-1801 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/01/1801/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/01/1801/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/01/1801/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/01/1801/1","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/01/1801/1 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"4ad3c71ec4bdad706332d0281a3bb3bba0234288","subject":"silence autoconf warnings about openvpnserv_testdriver_CFLAGS etc"}],"author":{"name":"Max Fillinger","email":"maximilian.fillinger@sentyron.com","date":"2026-07-07 09:02:06.000000000","tz":120},"committer":{"name":"Max Fillinger","email":"maximilian.fillinger@sentyron.com","date":"2026-07-22 12:49:51.000000000","tz":120},"subject":"Make --x509-username-field work with Mbed TLS","message":"Make --x509-username-field work with Mbed TLS\n\nIn pre-2.7 versions, this option was not available in the Mbed TLS\nbuild. This was changed in 2.7, but the option did not do anything when\nMbed TLS was selected as the crypto library. Regardless of the field\nchosen with --x509-username-field, OpenVPN would always extract the CN\nas username.\n\nThis could lead to a situation where an unintended certificate gets\naccepted by OpenVPN: If we run with \"--x509-username-field serialNumber\"\nand \"--verify-x509-name 0x05 name\", OpenVPN would accept a certificate\nwith CN\u003d0x05 and an incorrect serial number, while a certificate with\nthe correct serial number would be rejected. (Though note that to\nexploit this, an attacker needs to make the CA sign a certificate\nwith a hexadecimal number in the CN.)\n\nThis commit adds code to extract the correct field values from X509\ncertificates. It also adds unit tests for extracting the values of\ndifferent fields.\n\nDespite this commit fixing a CVE, we have decided not to keep it under\nembargo until the release of the next version because it is unlikely to\nbe exploitable in practice: Someone has to run OpenVPN 2.7 with Mbed\nTLS, use the --x509-username-field option even though it didn\u0027t exist in\nMbed TLS builds of earlier versions, not notice that the intended\ncertificate is *not* accepted, and then an attacker has to get the CA to\nsign a certificate with a weird common name.\n\nCVE: 2026-63650\nGithub: openvpn/openvpn-private-issues#144\nReported-By: Hcamael\nReported-By: 章鱼哥 (www.aipyaipy.com)\nChange-Id: Ic183f1f1f90561454b7b1128c95255368427cc4a\nSigned-off-by: Max Fillinger \u003cmaximilian.fillinger@sentyron.com\u003e\n"},"branch":"refs/heads/master"},"c2377404b5dc4a9c545ab38800bb5af606130c82":{"kind":"REWORK","_number":2,"created":"2026-07-22 13:15:52.000000000","uploader":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"ref":"refs/changes/01/1801/2","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/01/1801/2","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/01/1801/2 \u0026\u0026 git checkout -b change-1801 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/01/1801/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/01/1801/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/01/1801/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/01/1801/2","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/01/1801/2 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"4ad3c71ec4bdad706332d0281a3bb3bba0234288","subject":"silence autoconf warnings about openvpnserv_testdriver_CFLAGS etc"}],"author":{"name":"Max Fillinger","email":"maximilian.fillinger@sentyron.com","date":"2026-07-07 09:02:06.000000000","tz":120},"committer":{"name":"Max Fillinger","email":"maximilian.fillinger@sentyron.com","date":"2026-07-22 13:13:33.000000000","tz":120},"subject":"Make --x509-username-field work with Mbed TLS","message":"Make --x509-username-field work with Mbed TLS\n\nIn pre-2.7 versions, this option was not available in the Mbed TLS\nbuild. This was changed in 2.7, but the option did not do anything when\nMbed TLS was selected as the crypto library. Regardless of the field\nchosen with --x509-username-field, OpenVPN would always extract the CN\nas username.\n\nThis could lead to a situation where an unintended certificate gets\naccepted by OpenVPN: If we run with \"--x509-username-field serialNumber\"\nand \"--verify-x509-name 0x05 name\", OpenVPN would accept a certificate\nwith CN\u003d0x05 and an incorrect serial number, while a certificate with\nthe correct serial number would be rejected. (Though note that to\nexploit this, an attacker needs to make the CA sign a certificate\nwith a hexadecimal number in the CN.)\n\nThis commit adds code to extract the correct field values from X509\ncertificates. It also adds unit tests for extracting the values of\ndifferent fields.\n\nDespite this commit fixing a CVE, we have decided not to keep it under\nembargo until the release of the next version because it is unlikely to\nbe exploitable in practice: Someone has to run OpenVPN 2.7 with Mbed\nTLS, use the --x509-username-field option even though it didn\u0027t exist in\nMbed TLS builds of earlier versions, not notice that the intended\ncertificate is *not* accepted, and then an attacker has to get the CA to\nsign a certificate with a weird common name.\n\nCVE: 2026-63650\nGithub: openvpn/openvpn-private-issues#144\nReported-By: Hcamael\nReported-By: 章鱼哥 (www.aipyaipy.com)\nChange-Id: Ic183f1f1f90561454b7b1128c95255368427cc4a\nSigned-off-by: Max Fillinger \u003cmaximilian.fillinger@sentyron.com\u003e\n"},"branch":"refs/heads/master"},"e00d04feda433cd8d84584c85ab90f6f0cc6518a":{"kind":"REWORK","_number":3,"created":"2026-07-22 15:17:18.000000000","uploader":{"_account_id":1000030,"name":"MaxF","email":"max@max-fillinger.net","username":"MaxF"},"ref":"refs/changes/01/1801/3","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/01/1801/3","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/01/1801/3 \u0026\u0026 git checkout -b change-1801 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/01/1801/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/01/1801/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/01/1801/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/01/1801/3","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/01/1801/3 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"4ad3c71ec4bdad706332d0281a3bb3bba0234288","subject":"silence autoconf warnings about openvpnserv_testdriver_CFLAGS etc"}],"author":{"name":"Max Fillinger","email":"maximilian.fillinger@sentyron.com","date":"2026-07-07 09:02:06.000000000","tz":120},"committer":{"name":"Max Fillinger","email":"maximilian.fillinger@sentyron.com","date":"2026-07-22 15:09:04.000000000","tz":120},"subject":"Make --x509-username-field work with Mbed TLS","message":"Make --x509-username-field work with Mbed TLS\n\nIn pre-2.7 versions, this option was not available in the Mbed TLS\nbuild. This was changed in 2.7, but the option did not do anything when\nMbed TLS was selected as the crypto library. Regardless of the field\nchosen with --x509-username-field, OpenVPN would always extract the CN\nas username.\n\nThis could lead to a situation where an unintended certificate gets\naccepted by OpenVPN: If we run with \"--x509-username-field serialNumber\"\nand \"--verify-x509-name 0x05 name\", OpenVPN would accept a certificate\nwith CN\u003d0x05 and an incorrect serial number, while a certificate with\nthe correct serial number would be rejected. (Though note that to\nexploit this, an attacker needs to make the CA sign a certificate\nwith a hexadecimal number in the CN.)\n\nThis commit adds code to backend_x509_get_username to extract the\ncorrect field values from X509 certificates. It also changes the\nbehavior of the function to match the OpenSSL version when the output\nbuffer is too small. (With Mbed TLS, the function would silently\ntruncate the output and return SUCCESS.)\n\nIt also adds unit tests for extracting the values of different fields.\n\nDespite this commit fixing a CVE, we have decided not to keep it under\nembargo until the release of the next version because it is unlikely to\nbe exploitable in practice: Someone has to run OpenVPN 2.7 with Mbed\nTLS, use the --x509-username-field option even though it didn\u0027t exist in\nMbed TLS builds of earlier versions, not notice that the intended\ncertificate is *not* accepted, and then an attacker has to get the CA to\nsign a certificate with a weird common name.\n\nCVE: 2026-63650\nGithub: openvpn/openvpn-private-issues#144\nReported-By: Hcamael\nReported-By: 章鱼哥 (www.aipyaipy.com)\nChange-Id: Ic183f1f1f90561454b7b1128c95255368427cc4a\nSigned-off-by: Max Fillinger \u003cmaximilian.fillinger@sentyron.com\u003e\n"},"branch":"refs/heads/master"},"124ec07732bccc1fced2d8d37c71b761daf75f4f":{"kind":"NO_CODE_CHANGE","_number":4,"created":"2026-07-22 16:19:16.000000000","uploader":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"ref":"refs/changes/01/1801/4","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/01/1801/4","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/01/1801/4 \u0026\u0026 git checkout -b change-1801 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/01/1801/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/01/1801/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/01/1801/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/01/1801/4","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/01/1801/4 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"4ad3c71ec4bdad706332d0281a3bb3bba0234288","subject":"silence autoconf warnings about openvpnserv_testdriver_CFLAGS etc"}],"author":{"name":"Max Fillinger","email":"maximilian.fillinger@sentyron.com","date":"2026-07-22 15:25:14.000000000","tz":120},"committer":{"name":"Gert Doering","email":"gert@greenie.muc.de","date":"2026-07-22 15:59:23.000000000","tz":120},"subject":"Make --x509-username-field work with Mbed TLS","message":"Make --x509-username-field work with Mbed TLS\n\nIn pre-2.7 versions, this option was not available in the Mbed TLS\nbuild. This was changed in 2.7, but the option did not do anything when\nMbed TLS was selected as the crypto library. Regardless of the field\nchosen with --x509-username-field, OpenVPN would always extract the CN\nas username.\n\nThis could lead to a situation where an unintended certificate gets\naccepted by OpenVPN: If we run with \"--x509-username-field serialNumber\"\nand \"--verify-x509-name 0x05 name\", OpenVPN would accept a certificate\nwith CN\u003d0x05 and an incorrect serial number, while a certificate with\nthe correct serial number would be rejected. (Though note that to\nexploit this, an attacker needs to make the CA sign a certificate\nwith a hexadecimal number in the CN.)\n\nThis commit adds code to backend_x509_get_username to extract the\ncorrect field values from X509 certificates. It also changes the\nbehavior of the function to match the OpenSSL version when the output\nbuffer is too small. (With Mbed TLS, the function would silently\ntruncate the output and return SUCCESS.)\n\nIt also adds unit tests for extracting the values of different fields.\n\nDespite this commit fixing a CVE, we have decided not to keep it under\nembargo until the release of the next version because it is unlikely to\nbe exploitable in practice: Someone has to run OpenVPN 2.7 with Mbed\nTLS, use the --x509-username-field option even though it didn\u0027t exist in\nMbed TLS builds of earlier versions, not notice that the intended\ncertificate is *not* accepted, and then an attacker has to get the CA to\nsign a certificate with a weird common name.\n\nCVE: 2026-63650\nGithub: openvpn/openvpn-private-issues#144\nReported-By: Hcamael\nReported-By: 章鱼哥 (www.aipyaipy.com)\nChange-Id: Ic183f1f1f90561454b7b1128c95255368427cc4a\nSigned-off-by: Max Fillinger \u003cmaximilian.fillinger@sentyron.com\u003e\nAcked-by: Frank Lichtenheld \u003cfrank@lichtenheld.com\u003e\nGerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1801\nMessage-Id: \u003c20260722152521.22272-1-gert@greenie.muc.de\u003e\nURL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg37773.html\nSigned-off-by: Gert Doering \u003cgert@greenie.muc.de\u003e\n"},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[],"submit_requirements":[]}
