Blame
| e602b9 | uddr | 2026-04-22 21:02:49 | 1 | # CVE-2026-40215 - fix race condition in TLS handshake that could lead to leaking of packet data from a previous handshake under specific circumstances |
| 2 | ||||
| 3 | Ensure that buffer of freed session are not used |
|||
| 4 | ||||
| 5 | In a race condition an old TLS session could still try to send a packet but |
|||
| 6 | also get replaced by a new session. In this case, the buffer of the new |
|||
| 7 | session is still referenced. Add the check_session_buf_not_used function |
|||
| 8 | to mitigate this problem. |
|||
| 9 | ||||
| 10 | Also make the check if the to_link pointer is in one of the memory |
|||
| 11 | regions a bit better even though this not make a difference with the |
|||
| 12 | way we use these structs. But better safe than sorry. |
|||
| 13 | ||||
| 14 | A better solution to remove the TM_INITIAL state and handle reconnecting |
|||
| 15 | session in their own complete tls_multi is a more involved fix that requires |
|||
| 16 | a lot more refactoring. |
|||
| 17 | ||||
| 18 | OpenVPN version 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 are affected. This is fixed in version 2.6.20 and 2.7.2. |
|||
| 19 | ||||
| 20 | CVE Record: [CVE-2026-40215](https://www.cve.org/CVERecord?id=CVE-2026-40215) |
|||
| 21 | ||||
| 22 | Github: [OpenVPN/openvpn-private-issues#112](https://github.com/OpenVPN/openvpn-private-issues/issues/112) |
|||
| 23 | ||||
| 24 | Release notes: [openvpn-2.7.2](https://community.openvpn.net/ReleaseHistory#openvpn-272-released-22-april-2026) [openvpn-2.6.20](https://community.openvpn.net/ReleaseHistory#openvpn-2620-released-22-april-2026) |
|||
| 25 | ||||
| 26 | Reported-By: XlabAI Team of Tencent Xuanwu Lab (xlabai@tencent.com) |
|||
| 27 | ||||
| 28 | Reported-By: Guannan Wang (wgnbuaa@gmail.com |
|||
| 29 | ||||
| 30 | Reported-By: Zhanpeng Liu (pkugenuine@gmail.com) |
|||
| 31 | ||||
| 32 | Reported-By: Guancheng Li (lgcpku@gmail.com) |
