)]}'
{"id":"openvpn~1902","triplet_id":"openvpn~release%2F2.7~Iea1481e94ba1abe18c39d81cd797187c88427571","project":"openvpn","branch":"release/2.7","full_branch":"refs/heads/release/2.7","attention_set":{},"removed_from_attention_set":{"1000030":{"account":{"_account_id":1000030,"name":"Max Fillinger","email":"max@max-fillinger.net","username":"MaxF"},"last_update":"2026-09-17 17:26:32.000000000","reason":"Change was submitted"},"1000003":{"account":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"last_update":"2026-09-17 17:26:32.000000000","reason":"Change was submitted"},"1000035":{"account":{"_account_id":1000035,"name":"Steffan Karger","display_name":"Steffan Karger","email":"steffan@karger.me","username":"syzzer","status":"Commits and comments are my own views, not those of my employer."},"last_update":"2026-09-17 12:33:32.000000000","reason":"removed on reply"},"1000002":{"account":{"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"last_update":"2026-09-17 17:26:32.000000000","reason":"Change was submitted"}},"hashtags":[],"change_id":"Iea1481e94ba1abe18c39d81cd797187c88427571","subject":"Check for null-bytes in certificate subjects","status":"MERGED","created":"2026-09-07 11:42:30.000000000","updated":"2026-09-17 17:26:32.000000000","submitted":"2026-09-17 17:26:32.000000000","submitter":{"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"total_comment_count":11,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"1902","meta_rev_id":"50e920b40f81d613d5f5e5ad46a5a725917c312b","_number":1902,"virtual_id_number":1902,"owner":{"_account_id":1000030,"name":"Max Fillinger","email":"max@max-fillinger.net","username":"MaxF"},"actions":{},"labels":{"Code-Review":{"all":[{"value":0,"_account_id":1000035,"name":"Steffan Karger","display_name":"Steffan Karger","email":"steffan@karger.me","username":"syzzer","status":"Commits and comments are my own views, not those of my employer."},{"value":0,"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"}],"values":{"-2":"This shall not be submitted","-1":"I would prefer this is not submitted as is"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me, approved"},"description":"","default_value":0}},"removable_reviewers":[{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"}],"reviewers":{"REVIEWER":[{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},{"_account_id":1000035,"name":"Steffan Karger","display_name":"Steffan Karger","email":"steffan@karger.me","username":"syzzer","status":"Commits and comments are my own views, not those of my employer."}],"CC":[{"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-09-07 11:42:30.000000000","updated_by":{"_account_id":1000030,"name":"Max Fillinger","email":"max@max-fillinger.net","username":"MaxF"},"real_updated_by":{"_account_id":1000030,"name":"Max Fillinger","email":"max@max-fillinger.net","username":"MaxF"},"reviewer":{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"},"state":"CC"},{"updated":"2026-09-07 11:42:30.000000000","updated_by":{"_account_id":1000030,"name":"Max Fillinger","email":"max@max-fillinger.net","username":"MaxF"},"real_updated_by":{"_account_id":1000030,"name":"Max Fillinger","email":"max@max-fillinger.net","username":"MaxF"},"reviewer":{"_account_id":1000003,"name":"Arne Schwabe","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"state":"REVIEWER"},{"updated":"2026-09-07 12:40:25.000000000","updated_by":{"_account_id":1000035,"name":"Steffan Karger","display_name":"Steffan Karger","email":"steffan@karger.me","username":"syzzer","status":"Commits and comments are my own views, not those of my employer."},"real_updated_by":{"_account_id":1000035,"name":"Steffan Karger","display_name":"Steffan Karger","email":"steffan@karger.me","username":"syzzer","status":"Commits and comments are my own views, not those of my employer."},"reviewer":{"_account_id":1000035,"name":"Steffan Karger","display_name":"Steffan Karger","email":"steffan@karger.me","username":"syzzer","status":"Commits and comments are my own views, not those of my employer."},"state":"REVIEWER"},{"updated":"2026-09-17 09:49:30.000000000","updated_by":{"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"real_updated_by":{"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"reviewer":{"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"state":"CC"}],"messages":[{"id":"93f381143dc78d12a9badca2bcd22d8788ccfba6","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000030,"name":"Max Fillinger","email":"max@max-fillinger.net","username":"MaxF"},"date":"2026-09-07 11:42:30.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"6d621c45eb9a089a73f225e8c4dbcec60b78ce60","author":{"_account_id":1000035,"name":"Steffan Karger","display_name":"Steffan Karger","email":"steffan@karger.me","username":"syzzer","status":"Commits and comments are my own views, not those of my employer."},"date":"2026-09-07 12:40:25.000000000","message":"Patch Set 1: Code-Review-1\n\n(2 comments)","accounts_in_message":[],"_revision_number":1},{"id":"c1ae08a821712faa72373048af254765d7653b39","author":{"_account_id":1000030,"name":"Max Fillinger","email":"max@max-fillinger.net","username":"MaxF"},"date":"2026-09-07 12:54:20.000000000","message":"Patch Set 1:\n\n(1 comment)","accounts_in_message":[],"_revision_number":1},{"id":"157e0920bf6675214eb50a1d651503a2d15c6a73","author":{"_account_id":1000035,"name":"Steffan Karger","display_name":"Steffan Karger","email":"steffan@karger.me","username":"syzzer","status":"Commits and comments are my own views, not those of my employer."},"date":"2026-09-07 13:46:17.000000000","message":"Patch Set 1:\n\n(1 comment)","accounts_in_message":[],"_revision_number":1},{"id":"538bc928d290f4a73690ca7bab65b9aee22c7b31","author":{"_account_id":1000035,"name":"Steffan Karger","display_name":"Steffan Karger","email":"steffan@karger.me","username":"syzzer","status":"Commits and comments are my own views, not those of my employer."},"date":"2026-09-07 13:47:38.000000000","message":"Patch Set 1:\n\n(1 comment)","accounts_in_message":[],"_revision_number":1},{"id":"d8d585486911b1768bc9804b83cb61a72ff97938","author":{"_account_id":1000030,"name":"Max Fillinger","email":"max@max-fillinger.net","username":"MaxF"},"date":"2026-09-10 23:06:45.000000000","message":"Patch Set 1:\n\n(1 comment)","accounts_in_message":[],"_revision_number":1},{"id":"164fe1704ff097571d5cd6f9b62d9264c93e46ab","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000030,"name":"Max Fillinger","email":"max@max-fillinger.net","username":"MaxF"},"date":"2026-09-16 21:42:16.000000000","message":"Uploaded patch set 2.\n\nOutdated Votes:\n* Code-Review-1 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR is:MIN\")\n","accounts_in_message":[],"_revision_number":2},{"id":"b8a932c40e357654eb9bda0d73472a70868f8f85","author":{"_account_id":1000030,"name":"Max Fillinger","email":"max@max-fillinger.net","username":"MaxF"},"date":"2026-09-16 21:43:59.000000000","message":"Patch Set 2:\n\n(1 comment)","accounts_in_message":[],"_revision_number":2},{"id":"55e410778b03caad09ec25b5c9800ba083e71050","author":{"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"date":"2026-09-17 09:49:30.000000000","message":"Patch Set 2:\n\n(2 comments)","accounts_in_message":[],"_revision_number":2},{"id":"d67ee37740f8fa0dda410993ef1977291a31db5f","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000030,"name":"Max Fillinger","email":"max@max-fillinger.net","username":"MaxF"},"date":"2026-09-17 11:31:39.000000000","message":"Uploaded patch set 3.","accounts_in_message":[],"_revision_number":3},{"id":"3a0b8ba0db90be79c731ddb3742a1b2fb9b1e79a","author":{"_account_id":1000030,"name":"Max Fillinger","email":"max@max-fillinger.net","username":"MaxF"},"date":"2026-09-17 11:34:25.000000000","message":"Patch Set 3:\n\n(1 comment)","accounts_in_message":[],"_revision_number":3},{"id":"9f4a484eeb52f6c1a6b819316cd91a94eb12aa7b","author":{"_account_id":1000035,"name":"Steffan Karger","display_name":"Steffan Karger","email":"steffan@karger.me","username":"syzzer","status":"Commits and comments are my own views, not those of my employer."},"date":"2026-09-17 12:33:32.000000000","message":"Patch Set 3: Code-Review+2\n\n(1 comment)","accounts_in_message":[],"_revision_number":3},{"id":"50e920b40f81d613d5f5e5ad46a5a725917c312b","tag":"autogenerated:gerrit:merged","author":{"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"date":"2026-09-17 17:26:32.000000000","message":"Change has been successfully pushed.","accounts_in_message":[],"_revision_number":4}],"current_revision_number":4,"current_revision":"cf4384eef4676a01bd3ee98fa602f7b2af8079ea","revisions":{"efb1f77d28be164260bf4235949ee81f9aff5124":{"kind":"REWORK","_number":1,"created":"2026-09-07 11:42:30.000000000","uploader":{"_account_id":1000030,"name":"Max Fillinger","email":"max@max-fillinger.net","username":"MaxF"},"ref":"refs/changes/02/1902/1","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/02/1902/1","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/02/1902/1 \u0026\u0026 git checkout -b change-1902 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/02/1902/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/02/1902/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/02/1902/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/02/1902/1","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/02/1902/1 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"acd9702b6cdf94b173e78a6e310e408ffe33aec2","subject":"reliable: add unit tests for ACK and backoff DoS hardening"}],"author":{"name":"Max Fillinger","email":"maximilian.fillinger@sentyron.com","date":"2026-08-27 18:43:38.000000000","tz":120},"committer":{"name":"Max Fillinger","email":"maximilian.fillinger@sentyron.com","date":"2026-09-07 11:39:25.000000000","tz":120},"subject":"Check for null-bytes in certificate subjects","message":"Check for null-bytes in certificate subjects\n\nWhen using the OpenSSL library, we escaped embedded null-bytes in a\ncertificate\u0027s subject in x509_get_subject(), but in\nextract_x509_field_ssl(), we copied any null-bytes that are contained in\nthe field value. When using the option --verify-x509-name, this could\nlead to an incorrect name being accepted. For example, the common name\n\"admin\\0impersonator\" would be accepted when running with\n--verify-x509-name admin name.\n\nTo fix this, this commit makes x509_get_subject() return an error if the\nsubject contains an embedded null-byte. This way, OpenVPN won\u0027t connect\nwith peers that present such certificates.\n\nAs a defense-in-depth measure, we also check for null-bytes in\nextract_x509_field_ssl() in case a future version of OpenVPN has a code\npath that avoids x509_get_subject().\n\nWith Mbed TLS, the x509_get_subject() function already returned an error\nwhen there is an embedded null-byte. (As of Mbed TLS 3.5.) Here too, we\nadded a check for null-bytes to the function where we extract individual\nfields from the subject.\n\nAlso, backend_x509_get_username() is changed so that it returns the\nvalue of the *last* matching field, to be consistent with the behavior\nof the OpenSSL backend.\n\nThis is a partial backport of the commit\n\"Check for \\0 and RFC 2253 chars in cert subjects\" from the master\nbranch but skipping the part about escaping RFC 2253 characters to avoid\nuser-visible changes in a patch release. We do not consider the\nnull-byte check \"user-visible\" because we don\u0027t expect users to put\nnull-bytes into the common name.\n\nDiscovered and reported by BreachX Zero Day Labs, using Typhon AI Mil v2.\nContributing Researcher: Vivek Parikh.\n\nCVE: 2026-84790\nReported-by: Vivek Parikh \u003cvivek.parikh@breachx.ai\u003e\nGithub: OpenVPN/openvpn-private-issues#163\n\nChange-Id: Iea1481e94ba1abe18c39d81cd797187c88427571\nSigned-off-by: Max Fillinger \u003cmaximilian.fillinger@sentyron.com\u003e\n"},"branch":"refs/heads/release/2.7"},"124c4ffe53af78ba007ffe23de2f952fadfc30ae":{"kind":"REWORK","_number":2,"created":"2026-09-16 21:42:16.000000000","uploader":{"_account_id":1000030,"name":"Max Fillinger","email":"max@max-fillinger.net","username":"MaxF"},"ref":"refs/changes/02/1902/2","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/02/1902/2","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/02/1902/2 \u0026\u0026 git checkout -b change-1902 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/02/1902/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/02/1902/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/02/1902/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/02/1902/2","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/02/1902/2 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"acd9702b6cdf94b173e78a6e310e408ffe33aec2","subject":"reliable: add unit tests for ACK and backoff DoS hardening"}],"author":{"name":"Max Fillinger","email":"maximilian.fillinger@sentyron.com","date":"2026-08-27 18:43:38.000000000","tz":120},"committer":{"name":"Max Fillinger","email":"max@max-fillinger.net","date":"2026-09-16 21:38:33.000000000","tz":120},"subject":"Check for null-bytes in certificate subjects","message":"Check for null-bytes in certificate subjects\n\nWhen using the OpenSSL library, we escaped embedded null-bytes in a\ncertificate\u0027s subject in x509_get_subject(), but in\nextract_x509_field_ssl(), we copied any null-bytes that are contained in\nthe field value. When using the option --verify-x509-name, this could\nlead to an incorrect name being accepted. For example, the common name\n\"admin\\0impersonator\" would be accepted when running with\n--verify-x509-name admin name.\n\nTo fix this, this commit makes x509_get_subject() return an error if the\nsubject contains an embedded null-byte. This way, OpenVPN won\u0027t connect\nwith peers that present such certificates.\n\nAs a defense-in-depth measure, we also check for null-bytes in\nextract_x509_field_ssl() in case a future version of OpenVPN has a code\npath that avoids x509_get_subject().\n\nWith Mbed TLS, the x509_get_subject() function already returned an error\nwhen there is an embedded null-byte. (As of Mbed TLS 3.5.) Here too, we\nadded a check for null-bytes to the function where we extract individual\nfields from the subject.\n\nAlso, backend_x509_get_username() is changed so that it returns the\nvalue of the *last* matching field, to be consistent with the behavior\nof the OpenSSL backend.\n\nThis is a partial backport of the commit\n\"Check for \\0 and RFC 2253 chars in cert subjects\" from the master\nbranch but skipping the part about escaping RFC 2253 characters to avoid\nuser-visible changes in a patch release. We do not consider the\nnull-byte check \"user-visible\" because we don\u0027t expect users to put\nnull-bytes into the common name.\n\nv2: The previous version of the commit unescaped control characters in\nthe subject, so it had user-visible changes after all. This version\nescapes any control characters in the subject.\n\nDiscovered and reported by BreachX Zero Day Labs, using Typhon AI Mil v2.\nContributing Researcher: Vivek Parikh.\n\nCVE: 2026-84790\nReported-by: Vivek Parikh \u003cvivek.parikh@breachx.ai\u003e\nGithub: OpenVPN/openvpn-private-issues#163\n\nChange-Id: Iea1481e94ba1abe18c39d81cd797187c88427571\nSigned-off-by: Max Fillinger \u003cmaximilian.fillinger@sentyron.com\u003e\n"},"branch":"refs/heads/release/2.7"},"ed00063229719e8056263c1b2fbf05ccf7aaae19":{"kind":"REWORK","_number":3,"created":"2026-09-17 11:31:39.000000000","uploader":{"_account_id":1000030,"name":"Max Fillinger","email":"max@max-fillinger.net","username":"MaxF"},"ref":"refs/changes/02/1902/3","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/02/1902/3","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/02/1902/3 \u0026\u0026 git checkout -b change-1902 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/02/1902/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/02/1902/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/02/1902/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/02/1902/3","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/02/1902/3 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"acd9702b6cdf94b173e78a6e310e408ffe33aec2","subject":"reliable: add unit tests for ACK and backoff DoS hardening"}],"author":{"name":"Max Fillinger","email":"maximilian.fillinger@sentyron.com","date":"2026-08-27 18:43:38.000000000","tz":120},"committer":{"name":"Max Fillinger","email":"maximilian.fillinger@sentyron.com","date":"2026-09-17 11:28:43.000000000","tz":120},"subject":"Check for null-bytes in certificate subjects","message":"Check for null-bytes in certificate subjects\n\nWhen using the OpenSSL library, we escaped embedded null-bytes in a\ncertificate\u0027s subject in x509_get_subject(), but in\nextract_x509_field_ssl(), we copied any null-bytes that are contained in\nthe field value. When using the option --verify-x509-name, this could\nlead to an incorrect name being accepted. For example, the common name\n\"admin\\0impersonator\" would be accepted when running with\n--verify-x509-name admin name.\n\nTo fix this, this commit makes x509_get_subject() return an error if the\nsubject contains an embedded null-byte. This way, OpenVPN won\u0027t connect\nwith peers that present such certificates.\n\nAs a defense-in-depth measure, we also check for null-bytes in\nextract_x509_field_ssl() in case a future version of OpenVPN has a code\npath that avoids x509_get_subject().\n\nWith Mbed TLS, the x509_get_subject() function already returned an error\nwhen there is an embedded null-byte. (As of Mbed TLS 3.5.) Here too, we\nadded a check for null-bytes to the function where we extract individual\nfields from the subject.\n\nAlso, backend_x509_get_username() is changed so that it returns the\nvalue of the *last* matching field, to be consistent with the behavior\nof the OpenSSL backend.\n\nThis is a partial backport of the commit\n\"Check for \\0 and RFC 2253 chars in cert subjects\" from the master\nbranch but skipping the part about escaping RFC 2253 characters to avoid\nuser-visible changes in a patch release. We do not consider the\nnull-byte check \"user-visible\" because we don\u0027t expect users to put\nnull-bytes into the common name.\n\nv2: The previous version of the commit unescaped control characters in\nthe subject, so it had user-visible changes after all. This version\nescapes any control characters in the subject.\n\nDiscovered and reported by BreachX Zero Day Labs, using Typhon AI Mil v2.\nContributing Researcher: Vivek Parikh.\n\nCVE: 2026-84790\nReported-by: Vivek Parikh \u003cvivek.parikh@breachx.ai\u003e\nGithub: OpenVPN/openvpn-private-issues#163\n\nChange-Id: Iea1481e94ba1abe18c39d81cd797187c88427571\nSigned-off-by: Max Fillinger \u003cmaximilian.fillinger@sentyron.com\u003e\n"},"branch":"refs/heads/release/2.7"},"cf4384eef4676a01bd3ee98fa602f7b2af8079ea":{"kind":"TRIVIAL_REBASE_WITH_MESSAGE_UPDATE","_number":4,"created":"2026-09-17 17:26:32.000000000","uploader":{"_account_id":1000002,"name":"Gert Doering","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"ref":"refs/changes/02/1902/4","fetch":{"anonymous http":{"url":"https://gerrit.openvpn.net/openvpn","ref":"refs/changes/02/1902/4","commands":{"Branch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/02/1902/4 \u0026\u0026 git checkout -b change-1902 FETCH_HEAD","Checkout":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/02/1902/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/02/1902/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/02/1902/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull https://gerrit.openvpn.net/openvpn refs/changes/02/1902/4","Reset To":"git fetch https://gerrit.openvpn.net/openvpn refs/changes/02/1902/4 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"b0cb5029b2d9386568140792b5ce278a0e164ff2","subject":"ssl: do not trust the peer\u0027s request to resend the wrapped client key"}],"author":{"name":"Max Fillinger","email":"maximilian.fillinger@sentyron.com","date":"2026-09-17 12:46:05.000000000","tz":120},"committer":{"name":"Gert Doering","email":"gert@greenie.muc.de","date":"2026-09-17 17:13:42.000000000","tz":120},"subject":"Check for null-bytes in certificate subjects","message":"Check for null-bytes in certificate subjects\n\nWhen using the OpenSSL library, we escaped embedded null-bytes in a\ncertificate\u0027s subject in x509_get_subject(), but in\nextract_x509_field_ssl(), we copied any null-bytes that are contained in\nthe field value. When using the option --verify-x509-name, this could\nlead to an incorrect name being accepted. For example, the common name\n\"admin\\0impersonator\" would be accepted when running with\n--verify-x509-name admin name.\n\nTo fix this, this commit makes x509_get_subject() return an error if the\nsubject contains an embedded null-byte. This way, OpenVPN won\u0027t connect\nwith peers that present such certificates.\n\nAs a defense-in-depth measure, we also check for null-bytes in\nextract_x509_field_ssl() in case a future version of OpenVPN has a code\npath that avoids x509_get_subject().\n\nWith Mbed TLS, the x509_get_subject() function already returned an error\nwhen there is an embedded null-byte. (As of Mbed TLS 3.5.) Here too, we\nadded a check for null-bytes to the function where we extract individual\nfields from the subject.\n\nAlso, backend_x509_get_username() is changed so that it returns the\nvalue of the *last* matching field, to be consistent with the behavior\nof the OpenSSL backend.\n\nThis is a partial backport of the commit\n\"Check for \\0 and RFC 2253 chars in cert subjects\" from the master\nbranch but skipping the part about escaping RFC 2253 characters to avoid\nuser-visible changes in a patch release. We do not consider the\nnull-byte check \"user-visible\" because we don\u0027t expect users to put\nnull-bytes into the common name.\n\nv2: The previous version of the commit unescaped control characters in\nthe subject, so it had user-visible changes after all. This version\nescapes any control characters in the subject.\n\nDiscovered and reported by BreachX Zero Day Labs, using Typhon AI Mil v2.\nContributing Researcher: Vivek Parikh.\n\nCVE: 2026-84790\nReported-by: Vivek Parikh \u003cvivek.parikh@breachx.ai\u003e\nGithub: OpenVPN/openvpn-private-issues#163\n\nChange-Id: Iea1481e94ba1abe18c39d81cd797187c88427571\nSigned-off-by: Max Fillinger \u003cmaximilian.fillinger@sentyron.com\u003e\nAcked-by: Steffan Karger \u003csteffan@karger.me\u003e\nGerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1902\nMessage-Id: \u003c20260917124610.14291-1-gert@greenie.muc.de\u003e\nURL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg39304.html\nSigned-off-by: Gert Doering \u003cgert@greenie.muc.de\u003e\n"},"branch":"refs/heads/release/2.7"}},"requirements":[],"submit_records":[]}
