Commit e602b9

2026-04-22 21:02:49 uddr: CVE-2026-40215
/dev/null .. Security Announcements/CVE-2026-40215.md
@@ 0,0 1,32 @@
+ # CVE-2026-40215 - fix race condition in TLS handshake that could lead to leaking of packet data from a previous handshake under specific circumstances
+
+ Ensure that buffer of freed session are not used
+
+ In a race condition an old TLS session could still try to send a packet but
+ also get replaced by a new session. In this case, the buffer of the new
+ session is still referenced. Add the check_session_buf_not_used function
+ to mitigate this problem.
+
+ Also make the check if the to_link pointer is in one of the memory
+ regions a bit better even though this not make a difference with the
+ way we use these structs. But better safe than sorry.
+
+ A better solution to remove the TM_INITIAL state and handle reconnecting
+ session in their own complete tls_multi is a more involved fix that requires
+ a lot more refactoring.
+
+ OpenVPN version 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 are affected. This is fixed in version 2.6.20 and 2.7.2.
+
+ CVE Record: [CVE-2026-40215](https://www.cve.org/CVERecord?id=CVE-2026-40215)
+
+ Github: [OpenVPN/openvpn-private-issues#112](https://github.com/OpenVPN/openvpn-private-issues/issues/112)
+
+ Release notes: [openvpn-2.7.2](https://community.openvpn.net/ReleaseHistory#openvpn-272-released-22-april-2026) [openvpn-2.6.20](https://community.openvpn.net/ReleaseHistory#openvpn-2620-released-22-april-2026)
+
+ Reported-By: XlabAI Team of Tencent Xuanwu Lab (xlabai@tencent.com)
+
+ Reported-By: Guannan Wang (wgnbuaa@gmail.com
+
+ Reported-By: Zhanpeng Liu (pkugenuine@gmail.com)
+
+ Reported-By: Guancheng Li (lgcpku@gmail.com)
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9