For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_alpha2/Changes.rst)
Windows MSI changes since 2.7_alpha1:
-
* Includes fix for [CVE-2025-50054](https://www.cve.org/CVERecord/SearchResults?query=CVE-2025-50054)
+
* Includes fix for [CVE-2025-50054](https://www.cve.org/CVERecord?id=CVE-2025-50054)
* Built against OpenSSL 3.5.0
* Included openvpn-gui updated to 11.54.0.0
* Improve French (fr) and Turkish (tr) localization for OpenVPN GUI
@@ 64,7 64,7 @@
Security fixes:
-
* [CVE-2025-2704](https://www.cve.org/CVERecord/SearchResults?query=CVE-2025-2704): fix possible `ASSERT()` on OpenVPN servers using `--tls-crypt-v2`
+
* [CVE-2025-2704](https://www.cve.org/CVERecord?id=CVE-2025-2704): fix possible `ASSERT()` on OpenVPN servers using `--tls-crypt-v2`
Security scope: OpenVPN servers between 2.6.1 and 2.6.13 using
`--tls-crypt-v2` can be made to abort with an `ASSERT()` message by
sending a particular combination of authenticated and malformed packets.
@@ 86,7 86,7 @@
* Disable config in menu listing if its ovpn file becomes inaccessible (github [openvpn-gui#729](https://github.com/OpenVPN/openvpn-gui/issues/729))
Note: Windows MSI was updated to I002 on June 19th. Changes in I002:
-
* Includes fix for [CVE-2025-50054](https://www.cve.org/CVERecord/SearchResults?query=CVE-2025-50054)
+
* Includes fix for [CVE-2025-50054](https://www.cve.org/CVERecord?id=CVE-2025-50054)
| | | |
|-|-|-|
@@ 155,7 155,7 @@
Security fixes:
-
- [CVE-2024-5594](https://www.cve.org/CVERecord/SearchResults?query=CVE-2024-5594): control channel: refuse control channel messages with
+
- [CVE-2024-5594](https://www.cve.org/CVERecord?id=CVE-2024-5594): control channel: refuse control channel messages with
nonprintable characters in them. Security scope: a malicious openvpn peer can send garbage to openvpn log, or cause high CPU load.
(Reynir Björnsson)
@@ 204,17 204,17 @@
Security fixes:
-
* [CVE-2024-4877](https://www.cve.org/CVERecord/SearchResults?query=CVE-2024-4877): Windows: harden interactive service pipe.
+
* [CVE-2024-4877](https://www.cve.org/CVERecord?id=CVE-2024-4877): Windows: harden interactive service pipe.
Security scope: a malicious process with "some" elevated privileges
(!SeImpersonatePrivilege) could open the pipe a second time, tricking
openvn GUI into providing user credentials (tokens), getting full
access to the account openvpn-gui.exe runs as.
(Zeze with TeamT5)
-
* [CVE-2024-5594](https://www.cve.org/CVERecord/SearchResults?query=CVE-2024-5594): control channel: refuse control channel messages with
+
* [CVE-2024-5594](https://www.cve.org/CVERecord?id=CVE-2024-5594): control channel: refuse control channel messages with
nonprintable characters in them. Security scope: a malicious openvpn
peer can send garbage to openvpn log, or cause high CPU load.
(Reynir Björnsson)
-
* [CVE-2024-28882](https://www.cve.org/CVERecord/SearchResults?query=CVE-2024-28882): only call schedule_exit() once (on a given peer).
+
* [CVE-2024-28882](https://www.cve.org/CVERecord?id=CVE-2024-28882): only call schedule_exit() once (on a given peer).
Security scope: an authenticated client can make the server "keep the
session" even when the server has been told to disconnect this client
(Reynir Björnsson)
@@ 247,7 247,7 @@
* For the Windows-specific security fixes see above
* Built against OpenSSL 3.3.1
* Included openvpn-gui updated to 11.49.0.0
-
* Contains part of the fix for [CVE-2024-4877](https://www.cve.org/CVERecord/SearchResults?query=CVE-2024-4877)
+
* Contains part of the fix for [CVE-2024-4877](https://www.cve.org/CVERecord?id=CVE-2024-4877)
Note: Windows MSI was updated to I002 on June 26th. Changes in I002:
* Group names are localized in some localizations, so we have to use SIDs. (Github: [#671](https://github.com/OpenVPN/openvpn-build/issues/671))
@@ 270,20 270,20 @@
Security fixes:
-
* [CVE-2024-27459](https://www.cve.org/CVERecord/SearchResults?query=CVE-2024-27459): Windows: fix a possible stack overflow in the
+
* [CVE-2024-27459](https://www.cve.org/CVERecord?id=CVE-2024-27459): Windows: fix a possible stack overflow in the
interactive service component which might lead to a local privilege
escalation.
Reported-by: Vladimir Tokarev <vtokarev@microsoft.com>
-
* [CVE-2024-24974](https://www.cve.org/CVERecord/SearchResults?query=CVE-2024-24974): Windows: disallow access to the interactive service
+
* [CVE-2024-24974](https://www.cve.org/CVERecord?id=CVE-2024-24974): Windows: disallow access to the interactive service
pipe from remote computers.
Reported-by: Vladimir Tokarev <vtokarev@microsoft.com>
-
* [CVE-2024-27903](https://www.cve.org/CVERecord/SearchResults?query=CVE-2024-27903): Windows: disallow loading of plugins from untrusted
+
* [CVE-2024-27903](https://www.cve.org/CVERecord?id=CVE-2024-27903): Windows: disallow loading of plugins from untrusted
installation paths, which could be used to attack `openvpn.exe` via
a malicious plugin. Plugins can now only be loaded from the OpenVPN
install directory, the Windows system directory, and possibly from
a directory specified by `HKLM\SOFTWARE\OpenVPN\plugin_dir`.
Reported-by: Vladimir Tokarev <vtokarev@microsoft.com>
-
* [CVE-2024-1305](https://www.cve.org/CVERecord/SearchResults?query=CVE-2024-1305): Windows TAP driver: Fix potential integer overflow in !TapSharedSendPacket.
+
* [CVE-2024-1305](https://www.cve.org/CVERecord?id=CVE-2024-1305): Windows TAP driver: Fix potential integer overflow in !TapSharedSendPacket.
Reported-by: Vladimir Tokarev <vtokarev@microsoft.com>
Windows MSI changes since 2.5.10:
@@ 307,20 307,20 @@
Security fixes:
-
* [CVE-2024-27459](https://www.cve.org/CVERecord/SearchResults?query=CVE-2024-27459): Windows: fix a possible stack overflow in the
+
* [CVE-2024-27459](https://www.cve.org/CVERecord?id=CVE-2024-27459): Windows: fix a possible stack overflow in the
interactive service component which might lead to a local privilege
escalation.
Reported-by: Vladimir Tokarev <vtokarev@microsoft.com>
-
* [CVE-2024-24974](https://www.cve.org/CVERecord/SearchResults?query=CVE-2024-24974): Windows: disallow access to the interactive service
+
* [CVE-2024-24974](https://www.cve.org/CVERecord?id=CVE-2024-24974): Windows: disallow access to the interactive service
pipe from remote computers.
Reported-by: Vladimir Tokarev <vtokarev@microsoft.com>
-
* [CVE-2024-27903](https://www.cve.org/CVERecord/SearchResults?query=CVE-2024-27903): Windows: disallow loading of plugins from untrusted
+
* [CVE-2024-27903](https://www.cve.org/CVERecord?id=CVE-2024-27903): Windows: disallow loading of plugins from untrusted
installation paths, which could be used to attack `openvpn.exe` via
a malicious plugin. Plugins can now only be loaded from the OpenVPN
install directory, the Windows system directory, and possibly from
a directory specified by `HKLM\SOFTWARE\OpenVPN\plugin_dir`.
Reported-by: Vladimir Tokarev <vtokarev@microsoft.com>
-
* [CVE-2024-1305](https://www.cve.org/CVERecord/SearchResults?query=CVE-2024-1305): Windows TAP driver: Fix potential integer overflow in !TapSharedSendPacket.
+
* [CVE-2024-1305](https://www.cve.org/CVERecord?id=CVE-2024-1305): Windows TAP driver: Fix potential integer overflow in !TapSharedSendPacket.
Reported-by: Vladimir Tokarev <vtokarev@microsoft.com>
New features:
@@ 386,7 386,7 @@
Security fixes:
-
* Windows Installer: fix [CVE-2023-7235](https://www.cve.org/CVERecord/SearchResults?query=CVE-2023-7235) where installing to a non-default
+
* Windows Installer: fix [CVE-2023-7235](https://www.cve.org/CVERecord?id=CVE-2023-7235) where installing to a non-default
directory could lead to a local privilege escalation. Reported by Will Dormann.
New features:
@@ 483,8 483,8 @@
Security Fixes:
-
* [CVE-2023-46850](https://www.cve.org/CVERecord/SearchResults?query=CVE-2023-46850) OpenVPN versions between 2.6.0 and 2.6.6 incorrectly use a send buffer after it has been free()d in some circumstances, causing some free()d memory to be sent to the peer. All configurations using TLS (e.g. not using --secret) are affected by this issue. (found while tracking down CVE-2023-46849 / Github [#400](https://github.com/OpenVPN/openvpn/issues/400), [#417](https://github.com/OpenVPN/openvpn/issues/417))
-
* [CVE-2023-46849](https://www.cve.org/CVERecord/SearchResults?query=CVE-2023-46849) OpenVPN versions between 2.6.0 and 2.6.6 incorrectly restore `--fragment` configuration in some circumstances, leading to a division by zero when `--fragment` is used. On platforms where division by zero is fatal, this will cause an OpenVPN crash.
+
* [CVE-2023-46850](https://www.cve.org/CVERecord?id=CVE-2023-46850) OpenVPN versions between 2.6.0 and 2.6.6 incorrectly use a send buffer after it has been free()d in some circumstances, causing some free()d memory to be sent to the peer. All configurations using TLS (e.g. not using --secret) are affected by this issue. (found while tracking down CVE-2023-46849 / Github [#400](https://github.com/OpenVPN/openvpn/issues/400), [#417](https://github.com/OpenVPN/openvpn/issues/417))
+
* [CVE-2023-46849](https://www.cve.org/CVERecord?id=CVE-2023-46849) OpenVPN versions between 2.6.0 and 2.6.6 incorrectly restore `--fragment` configuration in some circumstances, leading to a division by zero when `--fragment` is used. On platforms where division by zero is fatal, this will cause an OpenVPN crash.