Good catch & thanks for the fix :-) - I am not commenting on the fix itself
(Arne knows the code much better there and if he's happy, so am I).  I did
test client/server side, with and without tls-crypt(-v2) and everything
still works - I did not try to reproduce the crash and see if the fix
works.  Also, unit test :-) - which passes fine on 2.6 up.

Your patch has been applied to the master, release/2.7 and release/2.6
branch (older versions do not have dynamic tls-crypt-v2).

commit bc7f77ea2b6a8e5d964f6cbb403e6bbf1fe77fa4 (master)
commit b0cb5029b2d9386568140792b5ce278a0e164ff2 (release/2.7)
commit 75fb978f97f1e8587f0d0d35843698a3df93cf09 (release/2.6)
Author: Lev Stipakov
Date:   Wed Sep 16 22:32:06 2026 +0200

     ssl: do not trust the peer's request to resend the wrapped client key

     Signed-off-by: Lev Stipakov <[email protected]>
     Acked-by: Arne Schwabe <[email protected]>
     Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1916
     Message-Id: <[email protected]>
     URL: 
https://www.mail-archive.com/[email protected]/msg39268.html
     Signed-off-by: Gert Doering <[email protected]>


--
kind regards,

Gert Doering



_______________________________________________
Openvpn-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-devel

Reply via email to