)]}'
{"id":"openvpn~1884","triplet_id":"openvpn~master~I6a886a1cac2d4725859dab2325cd362312ddc659","project":"openvpn","branch":"master","attention_set":{"1000002":{"account":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"last_update":"2026-08-31 08:57:17.000000000","reason":"Someone else replied on the change"}},"removed_from_attention_set":{"1000003":{"account":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"last_update":"2026-08-31 13:35:28.000000000","reason":"Change was submitted"}},"hashtags":[],"change_id":"I6a886a1cac2d4725859dab2325cd362312ddc659","subject":"dhcp: Fix off-by-one in write_dhcp_search_str() temp buffer guard","status":"MERGED","created":"2026-08-30 20:06:47.000000000","updated":"2026-08-31 13:35:28.000000000","submitted":"2026-08-31 13:35:28.000000000","submitter":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"total_comment_count":0,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"1884","meta_rev_id":"3543ceed88bac716f03b019b52c0ae6084c57983","_number":1884,"virtual_id_number":1884,"owner":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"actions":{},"labels":{"Code-Review":{"all":[{"value":0,"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},{"value":0,"_account_id":1000053,"name":"razvanc","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"}],"values":{"-2":"This shall not be submitted","-1":"I would prefer this is not submitted as is"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me, approved"},"description":"","default_value":0}},"removable_reviewers":[{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"}],"reviewers":{"REVIEWER":[{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},{"_account_id":1000053,"name":"razvanc","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"}],"CC":[{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-08-30 20:06:48.000000000","updated_by":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"reviewer":{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"},"state":"CC"},{"updated":"2026-08-30 20:06:48.000000000","updated_by":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"reviewer":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"state":"REVIEWER"},{"updated":"2026-08-31 08:57:17.000000000","updated_by":{"_account_id":1000053,"name":"razvanc","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},"reviewer":{"_account_id":1000053,"name":"razvanc","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},"state":"REVIEWER"}],"messages":[{"id":"286aaf9c9bc611956ec5f35b4a9353fe34a71878","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"date":"2026-08-30 20:06:47.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"e3017e6609cae2b45c3dfccc87a9b41485e20625","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"date":"2026-08-31 08:34:20.000000000","message":"Patch Set 2: Commit message was updated.","accounts_in_message":[],"_revision_number":2},{"id":"ae91ab2e80927d7a02e564b10b9224b48aef131f","author":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"date":"2026-08-31 08:34:24.000000000","message":"Patch Set 2: Code-Review+2","accounts_in_message":[],"_revision_number":2},{"id":"de2debe6195d66451adf5075edaf4310804eac2a","author":{"_account_id":1000053,"name":"razvanc","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},"date":"2026-08-31 08:57:17.000000000","message":"Patch Set 2: Code-Review+2","accounts_in_message":[],"_revision_number":2},{"id":"3543ceed88bac716f03b019b52c0ae6084c57983","tag":"autogenerated:gerrit:merged","author":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"date":"2026-08-31 13:35:28.000000000","message":"Change has been successfully pushed.","accounts_in_message":[],"_revision_number":3}],"current_revision_number":3,"current_revision":"1ece6fe6fd586501b486aac6932d424c167a3adb","revisions":{"38b64b3e3ca3389d31cf6854bf3536294800fe7f":{"kind":"REWORK","_number":1,"created":"2026-08-30 20:06:47.000000000","uploader":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"ref":"refs/changes/84/1884/1","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/84/1884/1","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/84/1884/1 \u0026\u0026 git checkout -b change-1884 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/84/1884/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/84/1884/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/84/1884/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/84/1884/1","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/84/1884/1 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"af6a79c6a83739ca9542e52a02a3449a2f292758","subject":"t_client.sh.in: Add ability to filter by test group"}],"author":{"name":"Nexory","email":"St4yl3r30@hotmail.de","date":"2026-08-10 15:48:07.000000000","tz":120},"committer":{"name":"Gert Doering","email":"gert@greenie.muc.de","date":"2026-08-30 20:04:40.000000000","tz":120},"subject":"dhcp: Fix off-by-one in write_dhcp_search_str() temp buffer guard","message":"dhcp: Fix off-by-one in write_dhcp_search_str() temp buffer guard\n\nEach search list entry consumes strlen(ptr) + 2 bytes of tmp_buf: one\nleading label length byte, the domain characters, and one trailing NUL.\nThe guard only accounted for strlen(ptr) + 1, so a sequence of entries\nwhose accumulated length lands exactly on the boundary passed the check\nand then wrote tmp_buf[256], one byte past the 256 byte array.\n\nThe existing \"len \u003e 255\" check enforces the correct upper bound, but it\nruns after that write has already happened.\n\nThe entries can be pushed by the server: --dhcp-option falls under\nOPT_P_DHCPDNS, which pull_permission_mask() includes, and\nvalidate_domain() imposes no length limit.\n\nReproduced under AddressSanitizer, which reports a one byte\nstack-buffer-overflow at dhcp.c:308. The added unit test covers the\nboundary; it fails before this change and passes after it. The two\nexisting cases marked \"maximum length\" are unaffected, since a 253\ncharacter domain still satisfies 253 + 0 + 2 \u003c\u003d 256.\n\nThis was reported independently by Andre Kropp and Chính Nguyễn Văn.\nPatch author is Andre Kropp, recording the second report in the Reported-By:\n\nCVE: 2026-81738\nChange-Id: I6a886a1cac2d4725859dab2325cd362312ddc659\nSigned-off-by: Nexory \u003cSt4yl3r30@hotmail.de\u003e\nReported-By: Andre Kropp (Nexory)\nReported-By: ChinhNguyen\n"},"branch":"refs/heads/master"},"77f457a7dfea2bb62967dea5c43be238d4249be0":{"kind":"NO_CODE_CHANGE","_number":2,"created":"2026-08-31 08:34:20.000000000","uploader":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"ref":"refs/changes/84/1884/2","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/84/1884/2","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/84/1884/2 \u0026\u0026 git checkout -b change-1884 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/84/1884/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/84/1884/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/84/1884/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/84/1884/2","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/84/1884/2 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"af6a79c6a83739ca9542e52a02a3449a2f292758","subject":"t_client.sh.in: Add ability to filter by test group"}],"author":{"name":"Nexory","email":"St4yl3r30@hotmail.de","date":"2026-08-10 15:48:07.000000000","tz":120},"committer":{"name":"cron2","email":"gert@greenie.muc.de","date":"2026-08-31 08:34:20.000000000","tz":0},"subject":"dhcp: Fix off-by-one in write_dhcp_search_str() temp buffer guard","message":"dhcp: Fix off-by-one in write_dhcp_search_str() temp buffer guard\n\nEach search list entry consumes strlen(ptr) + 2 bytes of tmp_buf: one\nleading label length byte, the domain characters, and one trailing NUL.\nThe guard only accounted for strlen(ptr) + 1, so a sequence of entries\nwhose accumulated length lands exactly on the boundary passed the check\nand then wrote tmp_buf[256], one byte past the 256 byte array.\n\nThe existing \"len \u003e 255\" check enforces the correct upper bound, but it\nruns after that write has already happened.\n\nThe entries can be pushed by the server: --dhcp-option falls under\nOPT_P_DHCPDNS, which pull_permission_mask() includes, and\nvalidate_domain() imposes no length limit.\n\nReproduced under AddressSanitizer, which reports a one byte\nstack-buffer-overflow at dhcp.c:308. The added unit test covers the\nboundary; it fails before this change and passes after it. The two\nexisting cases marked \"maximum length\" are unaffected, since a 253\ncharacter domain still satisfies 253 + 0 + 2 \u003c\u003d 256.\n\nThis was reported independently by Andre Kropp and Chính Nguyễn Văn.\nPatch author is Andre Kropp, recording both reports in the Reported-By:\n\nCVE: 2026-81738\nChange-Id: I6a886a1cac2d4725859dab2325cd362312ddc659\nSigned-off-by: Nexory \u003cSt4yl3r30@hotmail.de\u003e\nReported-By: Andre Kropp (Nexory)\nReported-By: ChinhNguyen\n"},"branch":"refs/heads/master","description":"Edit commit message"},"1ece6fe6fd586501b486aac6932d424c167a3adb":{"kind":"NO_CODE_CHANGE","_number":3,"created":"2026-08-31 13:35:28.000000000","uploader":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"ref":"refs/changes/84/1884/3","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/84/1884/3","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/84/1884/3 \u0026\u0026 git checkout -b change-1884 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/84/1884/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/84/1884/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/84/1884/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/84/1884/3","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/84/1884/3 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"af6a79c6a83739ca9542e52a02a3449a2f292758","subject":"t_client.sh.in: Add ability to filter by test group"}],"author":{"name":"Nexory","email":"St4yl3r30@hotmail.de","date":"2026-08-31 08:34:40.000000000","tz":120},"committer":{"name":"Gert Doering","email":"gert@greenie.muc.de","date":"2026-08-31 13:13:55.000000000","tz":120},"subject":"dhcp: Fix off-by-one in write_dhcp_search_str() temp buffer guard","message":"dhcp: Fix off-by-one in write_dhcp_search_str() temp buffer guard\n\nEach search list entry consumes strlen(ptr) + 2 bytes of tmp_buf: one\nleading label length byte, the domain characters, and one trailing NUL.\nThe guard only accounted for strlen(ptr) + 1, so a sequence of entries\nwhose accumulated length lands exactly on the boundary passed the check\nand then wrote tmp_buf[256], one byte past the 256 byte array.\n\nThe existing \"len \u003e 255\" check enforces the correct upper bound, but it\nruns after that write has already happened.\n\nThe entries can be pushed by the server: --dhcp-option falls under\nOPT_P_DHCPDNS, which pull_permission_mask() includes, and\nvalidate_domain() imposes no length limit.\n\nReproduced under AddressSanitizer, which reports a one byte\nstack-buffer-overflow at dhcp.c:308. The added unit test covers the\nboundary; it fails before this change and passes after it. The two\nexisting cases marked \"maximum length\" are unaffected, since a 253\ncharacter domain still satisfies 253 + 0 + 2 \u003c\u003d 256.\n\nThis was reported independently by Andre Kropp and Chính Nguyễn Văn.\nPatch author is Andre Kropp, recording both reports in the Reported-By:\n\nCVE: 2026-81738\nChange-Id: I6a886a1cac2d4725859dab2325cd362312ddc659\nSigned-off-by: Nexory \u003cSt4yl3r30@hotmail.de\u003e\nAcked-by: Gert Doering \u003cgert@greenie.muc.de\u003e\nAcked-by: Razvan Cojocaru \u003crazvanc@mailbox.org\u003e\nGerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1884\nReported-By: Andre Kropp (Nexory)\nReported-By: ChinhNguyen\nMessage-Id: \u003c20260831083449.12484-1-gert@greenie.muc.de\u003e\nSigned-off-by: Gert Doering \u003cgert@greenie.muc.de\u003e\n"},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[],"submit_requirements":[]}
