CVE-2026-84790
Public on 2026-10-09
Modified on 2026-10-09
Description
When using the OpenSSL library, we escaped embedded null-bytes in a certificate's subject in x509_get_subject(), but in extract_x509_field_ssl(), we copied any null-bytes that are contained in the field value. When using the option --verify-x509-name, this could lead to an incorrect name being accepted. For example, the common name "admin\0impersonator" would be accepted when running with --verify-x509-name admin name.
Fixed by: https://github.com/OpenVPN/openvpn/commit/cf4384eef4676a01bd3ee98fa602f7b2af8079ea (v2.7.8)
Fixed by: https://github.com/OpenVPN/openvpn/commit/cf4384eef4676a01bd3ee98fa602f7b2af8079ea (v2.7.8)
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2023 | openvpn | Pending Fix | ||
| Amazon Linux 2027 Preview | openvpn | Pending Fix |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 7.4 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |