From: rootvector2 Date: Wed, 15 Jul 2026 20:22:02 +0000 (+0200) Subject: proto: correct 802.1Q length check in is_ipv_X X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=f8b15dad1258d6cf71ffa16f67efd9f8b57b9727;p=thirdparty%2Fopenvpn.git proto: correct 802.1Q length check in is_ipv_X Github: OpenVPN/openvpn#1044 This has also been reported twice as a security relevant bug, but only later than the original finding - and it isn't. While --client-nat would modify a 32bit integer "after the packet" (the place where an IPv4 address would be, in a well-formed packet), the underlying buffer is always max-frame sized, and we never look at the "modified integer" afterwards, so there are no consequences warranting allocation of a CVE ID. Signed-off-by: rootvector2 Acked-by: Arne Schwabe Acked-by: Antonio Quartulli Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1789 Reported-By: 章鱼哥 (www.aipyaipy.com) Reported-By: Yu Zhang Wong Change-Id: I8219c6295acf28ff10ddb2fcc285f813c42fa8fe Message-Id: <20260715202210.9010-1-gert@greenie.muc.de> URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg37652.html Signed-off-by: Gert Doering --- diff --git a/src/openvpn/proto.c b/src/openvpn/proto.c index 13fe0a548..785c021ff 100644 --- a/src/openvpn/proto.c +++ b/src/openvpn/proto.c @@ -70,7 +70,7 @@ is_ipv_X(int tunnel_type, struct buffer *buf, int ip_ver) if (proto == htons(OPENVPN_ETH_P_8021Q)) { const struct openvpn_8021qhdr *evh; - if (BLENZ(buf) < sizeof(struct openvpn_ethhdr) + sizeof(struct openvpn_iphdr)) + if (BLENZ(buf) < sizeof(struct openvpn_8021qhdr) + sizeof(struct openvpn_iphdr)) { return false; }