)]}'
{"id":"openvpn~1886","triplet_id":"openvpn~master~Ic983a3bf1ee8d4ef98f3883d5e5ddf234696a182","project":"openvpn","branch":"master","attention_set":{},"removed_from_attention_set":{"1000003":{"account":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"last_update":"2026-09-01 12:38:06.000000000","reason":"Change was submitted"},"1000002":{"account":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"last_update":"2026-09-01 12:38:06.000000000","reason":"Change was submitted"},"1000006":{"account":{"_account_id":1000006,"name":"d12fk","display_name":"Heiko Hund","email":"heiko@openvpn.net","username":"d12fk"},"last_update":"2026-09-01 12:38:06.000000000","reason":"Change was submitted"}},"hashtags":[],"change_id":"Ic983a3bf1ee8d4ef98f3883d5e5ddf234696a182","subject":"openvpnserv: harden CheckConfigPath() a bit more","status":"MERGED","created":"2026-08-31 16:03:00.000000000","updated":"2026-09-01 12:38:06.000000000","submitted":"2026-09-01 12:38:06.000000000","submitter":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"total_comment_count":0,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"1886","meta_rev_id":"d442772b4e62403f03850be50117d436e1d2bc0e","_number":1886,"virtual_id_number":1886,"owner":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"actions":{},"labels":{"Code-Review":{"all":[{"value":0,"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},{"value":0,"_account_id":1000053,"name":"razvanc","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"}],"values":{"-2":"This shall not be submitted","-1":"I would prefer this is not submitted as is"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me, approved"},"description":"","default_value":0}},"removable_reviewers":[{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"}],"reviewers":{"REVIEWER":[{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},{"_account_id":1000053,"name":"razvanc","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"}],"CC":[{"_account_id":1000006,"name":"d12fk","display_name":"Heiko Hund","email":"heiko@openvpn.net","username":"d12fk"},{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-08-31 16:03:00.000000000","updated_by":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"reviewer":{"_account_id":1000006,"name":"d12fk","display_name":"Heiko Hund","email":"heiko@openvpn.net","username":"d12fk"},"state":"REVIEWER"},{"updated":"2026-08-31 16:03:01.000000000","updated_by":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"reviewer":{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"},"state":"CC"},{"updated":"2026-08-31 16:03:01.000000000","updated_by":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"reviewer":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"state":"REVIEWER"},{"updated":"2026-08-31 17:12:40.000000000","updated_by":{"_account_id":1000053,"name":"razvanc","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},"reviewer":{"_account_id":1000053,"name":"razvanc","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},"state":"REVIEWER"},{"updated":"2026-09-01 12:38:06.000000000","updated_by":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"reviewer":{"_account_id":1000006,"name":"d12fk","display_name":"Heiko Hund","email":"heiko@openvpn.net","username":"d12fk"},"state":"CC"}],"messages":[{"id":"b0c83ee3be1d9d51ad3c51d79636d1c925766839","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"date":"2026-08-31 16:03:00.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"5d2c746515bb4d0666d9af705c0bb1103e51362f","author":{"_account_id":1000053,"name":"razvanc","display_name":"Razvan Cojocaru","email":"razvanc@mailbox.org","username":"razvanc"},"date":"2026-08-31 17:12:40.000000000","message":"Patch Set 1: Code-Review+2","accounts_in_message":[],"_revision_number":1},{"id":"d442772b4e62403f03850be50117d436e1d2bc0e","tag":"autogenerated:gerrit:merged","author":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"date":"2026-09-01 12:38:06.000000000","message":"Change has been successfully pushed.","accounts_in_message":[],"_revision_number":2}],"current_revision_number":2,"current_revision":"588af513aac1d2d774fd3fde1716384e3501a5a1","revisions":{"d1e87a4b4ec6a953063ff9be501595571c17d921":{"kind":"REWORK","_number":1,"created":"2026-08-31 16:03:00.000000000","uploader":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"ref":"refs/changes/86/1886/1","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/86/1886/1","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/86/1886/1 \u0026\u0026 git checkout -b change-1886 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/86/1886/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/86/1886/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/86/1886/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/86/1886/1","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/86/1886/1 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"c2db629bb5909a15c7408b3bca7971dbc3c8b1d1","subject":"openvpnserv: don\u0027t allow \u0027/\u0027 in config paths"}],"author":{"name":"Heiko Hund","email":"heiko@ist.eigentlich.net","date":"2026-08-21 13:29:55.000000000","tz":120},"committer":{"name":"Gert Doering","email":"gert@greenie.muc.de","date":"2026-08-31 15:59:38.000000000","tz":120},"subject":"openvpnserv: harden CheckConfigPath() a bit more","message":"openvpnserv: harden CheckConfigPath() a bit more\n\nIf the config_path retrieved from the Registry doesn\u0027t end with a path\nsepatator, the prefix check could be satisfied by a sibling directory\nthat starts with the same substring, e.g. \"config\" vs. \"configx\". While\ncode in common.c ensures this, that code could disappear in the future\nleaving the check vulnerable. Instead spend the few CPU cycles to be\nabsolutely sure, we\u0027re doing the right thing here.\n\nDiscovered and reported by BreachX Zero Day Labs, using Typhon AI Mil v2.\nContributing Researcher: Vivek Parikh.\n\nReported-by: Vivek Parikh \u003cvivek.parikh@breachx.ai\u003e\nCVE: 2026-78043\nChange-Id: Ic983a3bf1ee8d4ef98f3883d5e5ddf234696a182\nSigned-off-by: Heiko Hund \u003cheiko@ist.eigentlich.net\u003e\n"},"branch":"refs/heads/master"},"588af513aac1d2d774fd3fde1716384e3501a5a1":{"kind":"NO_CODE_CHANGE","_number":2,"created":"2026-09-01 12:38:06.000000000","uploader":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"ref":"refs/changes/86/1886/2","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/86/1886/2","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/86/1886/2 \u0026\u0026 git checkout -b change-1886 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/86/1886/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/86/1886/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/86/1886/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/86/1886/2","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/86/1886/2 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"eecebd88a38ffe1571d1a259da87f611b7b08e9c","subject":"openvpnserv: don\u0027t allow \u0027/\u0027 in config paths"}],"author":{"name":"Heiko Hund","email":"heiko@ist.eigentlich.net","date":"2026-08-31 18:47:04.000000000","tz":120},"committer":{"name":"Gert Doering","email":"gert@greenie.muc.de","date":"2026-09-01 12:36:02.000000000","tz":120},"subject":"openvpnserv: harden CheckConfigPath() a bit more","message":"openvpnserv: harden CheckConfigPath() a bit more\n\nIf the config_path retrieved from the Registry doesn\u0027t end with a path\nsepatator, the prefix check could be satisfied by a sibling directory\nthat starts with the same substring, e.g. \"config\" vs. \"configx\". While\ncode in common.c ensures this, that code could disappear in the future\nleaving the check vulnerable. Instead spend the few CPU cycles to be\nabsolutely sure, we\u0027re doing the right thing here.\n\nDiscovered and reported by BreachX Zero Day Labs, using Typhon AI Mil v2.\nContributing Researcher: Vivek Parikh.\n\nReported-by: Vivek Parikh \u003cvivek.parikh@breachx.ai\u003e\nTested-by: Vivek Parikh \u003cvivek.parikh@breachx.ai\u003e\nCVE: 2026-78043\nChange-Id: Ic983a3bf1ee8d4ef98f3883d5e5ddf234696a182\nSigned-off-by: Heiko Hund \u003cheiko@ist.eigentlich.net\u003e\nAcked-by: Razvan Cojocaru \u003crazvanc@mailbox.org\u003e\nAcked-by: Arne Schwabe \u003carne@rfc2549.org\u003e\nGerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1886\nMessage-Id: \u003c20260831184709.3359-1-gert@greenie.muc.de\u003e\nURL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg38854.html\nSigned-off-by: Gert Doering \u003cgert@greenie.muc.de\u003e\n"},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[],"submit_requirements":[]}
