ACK ("stared at code"). Have no ASAN setup here so replicating the original problem involved a bit of extra msg()'ing and then scratching my head, but I can confirm that the original math ended up with an integer underflow / unsigned, and the comarison not firing...
Your patch has been applied to the master, release/2.4 and release/2.3 branch. commit e6bf7e033d063535a4414a4cf49c8f367ecdbb4f (master) commit b52c1ff43b23c3cf438fb99b807a7309d3229a56 (release/2.4) commit 236807276368514f8ab80155f440a1d377ab412b (release/2.3) Author: Steffan Karger Date: Mon May 22 15:54:13 2017 +0200 openssl: fix overflow check for long --tls-cipher option Signed-off-by: Steffan Karger <steffan.kar...@fox-it.com> Acked-by: Gert Doering <g...@greenie.muc.de> Message-Id: <1495461253-20111-1-git-send-email-steffan.kar...@fox-it.com> URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg14716.html Signed-off-by: Gert Doering <g...@greenie.muc.de> -- kind regards, Gert Doering ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot _______________________________________________ Openvpn-devel mailing list Openvpn-devel@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openvpn-devel