From: Arne Schwabe Date: Fri, 31 Jul 2026 10:08:09 +0000 (+0200) Subject: Add check that username is identical to multi float X-Git-Url: http://git.ipfire.org/index.cgi?a=commitdiff_plain;h=HEAD;p=thirdparty%2Fopenvpn.git Add check that username is identical to multi float This adds an additional safe guard for setups that do not use client certificates. Change-Id: Ie552084638320b3bace76be2f589013f12af3c46 Signed-off-by: Arne Schwabe Acked-by: Frank Lichtenheld Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1724 Message-Id: <20260731100815.3406-1-gert@greenie.muc.de> URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg38095.html Signed-off-by: Gert Doering --- diff --git a/src/openvpn/multi.c b/src/openvpn/multi.c index f5a18f73e..20b4f1499 100644 --- a/src/openvpn/multi.c +++ b/src/openvpn/multi.c @@ -3111,6 +3111,18 @@ multi_check_dest_addr_allowed(struct multi_context *m, struct multi_instance *mi goto done; } + /* do not allow if target address has a different username */ + if (m1->locked_username || m2->locked_username) + { + if (!m1->locked_username || !m2->locked_username + || strcmp(m1->locked_username, m2->locked_username) != 0) + { + msg(D_MULTI_LOW, "Disallow float to an address taken by another client %s", + multi_instance_string(ex_mi, false, &gc)); + goto done; + } + } + /* It doesn't make sense to let a peer float to the address it already * has, so we disallow it. This can happen if a DCO netlink notification * gets lost and we miss a floating step. @@ -3127,7 +3139,7 @@ multi_check_dest_addr_allowed(struct multi_context *m, struct multi_instance *mi msg(D_MULTI_LOW, "closing instance %s due to float collision with %s " - "using the same certificate", + "using the same certificate and username", multi_instance_string(ex_mi, false, &gc), multi_instance_string(mi, false, &gc)); multi_close_instance(m, ex_mi, false); ret = true;