Commit 05fd00

2026-08-05 19:38:48 flichtenheld: 2.7.6+2.6.22
ReleaseHistory.md ..
@@ 1,3 1,139 @@
+ ## OpenVPN 2.7.6 -- Released 5 August 2026
+ The OpenVPN community project team is proud to release OpenVPN 2.7.6. This is a bugfix release fixing
+ several security issues.
+
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7.6/Changes.rst)
+
+ Security fixes:
+
+ - openvpnserv (windows): better scrutinize command line passed in
+ from the control socket to openvpn. This would lead to circumventing
+ admin restrictions on allowed openvpn config directories (but never
+ to "read files the user has no permissions for") ([CVE-2026-63649](https://www.cve.org/CVERecord?id=CVE-2026-63649))
+
+ Bug found by 章鱼哥 (www.aipyaipy.com)
+
+ - dco: make key state desync recoverable
+
+ This was reported as a "with suitable timing, a key-update de-sync between
+ OpenVPN and the kernel could trigger an ASSERT()", and was initially
+ handled as security report. It turned out to be not exploitable, but the
+ state machine was not very robust and so the opportunity was used to
+ improve the code.
+
+ Bug found by 章鱼哥 (www.aipyaipy.com)
+
+ - make ``--x509-username-field`` work with mbedTLS.
+
+ In very particular setups, together with a CA creating matching certificates,
+ this could lead to unintentionally permitting a certificate that should
+ not have. This is why this was considered a (low-prio) security bug and a
+ CVE ID was assigned ([CVE-2026-63650](https://www.cve.org/CVERecord?id=CVE-2026-63650))
+
+ Bug found by 章鱼哥 (www.aipyaipy.com)
+
+ User-visible Changes:
+
+ - if `--dev` is not specified, default to `--dev tun` - so for the
+ tun case, this option can now be left out of the openvpn config.
+
+ - `--ping` and `--keepalive` settings are now limited to 24 hours
+ maximum - the primary reason for that is to avoid lots of extra code
+ in the DCO kernel to handle arbitrarily large values without overflowing
+ 32 bit integers. 24h is considered much higher than any reasonable use.
+
+ - The `TCP_NODELAY` socket flag is now "always on". The `--tcp-nodelay`
+ option is kept, because setting it on a p2mp server also enables pushing
+ of `socket-flags TCP_NODELAY` to clients, which might not have this
+ code change yet.
+
+ - Remove `--providers` from `--help` output on mbedTLS builds.
+
+ Bugfixes:
+
+ - refuse incoming HARD RESET packets with a sequence ID != 0
+ (this is basically making an OpenVPN server ignore and log a
+ "should never happen" client-side misbehaviour, which could lead to
+ TLS handshake establishment failures in p2p TLS setups)
+
+ - correctly calculate packet id size if epoch packet format is in use -
+ this was off by 4, for connections openvpn 2.7+ to openvpn 2.7+,
+ exceeding "mssfix mtu" headroom by those 4 bytes
+ (Github: [OpenVPN/openvpn#1074](https://github.com/OpenVPN/openvpn/issues/1074))
+
+ - correct minimum packet length check for 802.1q tagged packets
+ (Github: [OpenVPN/openvpn#1044](https://github.com/OpenVPN/openvpn/issues/1044)).
+
+ This was also reported (twice) as a security bug, as technically
+ OpenVPN with `--client-nat` would read and write up to 4 bytes
+ "after the end of the packet" - but due to the OpenVPN packet buffer
+ layouts, which are always full-frame-sized this is fully safe and has
+ no adverse consequences.
+
+
+ Windows MSI changes since 2.7.5-I001:
+ * Update included dco-win driver to v2.8.4
+ * fix control channel stall (Github: [ovpn-dco-win/issues/137](https://github.com/OpenVPN/ovpn-dco-win/issues/137))
+
+ | | | |
+ |-|-|-|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.6-I001-amd64.msi.asc)|[OpenVPN-2.7.6-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.6-I001-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.6-I001-arm64.msi.asc)|[OpenVPN-2.7.6-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.6-I001-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.6-I001-x86.msi.asc)|[OpenVPN-2.7.6-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.6-I001-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7.6.tar.gz.asc)|[openvpn-2.7.6.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7.6.tar.gz)|
+
+ For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
+
+ ## OpenVPN 2.6.22 -- Released 5 August 2026
+ The OpenVPN community project team is proud to release OpenVPN 2.6.22. This is a bugfix release fixing
+ several security issues.
+
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.22/Changes.rst)
+
+ Security fixes:
+
+ - openvpnserv (windows): better scrutinize command line passed in
+ from the control socket to openvpn. This would lead to circumventing
+ admin restrictions on allowed openvpn config directories (but never
+ to "read files the user has no permissions for") ([CVE-2026-63649](https://www.cve.org/CVERecord?id=CVE-2026-63649))
+
+ Bug found by 章鱼哥 (www.aipyaipy.com)
+
+ - dco: make key state desync recoverable
+
+ This was reported as a "with suitable timing, a key-update de-sync between
+ OpenVPN and the kernel could trigger an ASSERT()", and was initially
+ handled as security report. It turned out to be not exploitable, but the
+ state machine was not very robust and so the opportunity was used to
+ improve the code.
+
+ Bug found by 章鱼哥 (www.aipyaipy.com)
+
+ Bugfixes:
+
+ - refuse incoming HARD RESET packets with a sequence ID != 0
+ (this is basically making an OpenVPN server ignore and log a
+ "should never happen" client-side misbehaviour, which could lead to
+ TLS handshake establishment failures in p2p TLS setups)
+
+ - correct minimum packet length check for 802.1q tagged packets
+ (Github: [OpenVPN/openvpn#1044](https://github.com/OpenVPN/openvpn/issues/1044)).
+
+ This was also reported (twice) as a security bug, as technically
+ OpenVPN with `--client-nat` would read and write up to 4 bytes
+ "after the end of the packet" - but due to the OpenVPN packet buffer
+ layouts, which are always full-frame-sized this is fully safe and has
+ no adverse consequences.
+
+
+ | | | |
+ |-|-|-|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.22-I001-amd64.msi.asc)|[OpenVPN-2.6.22-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.22-I001-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.22-I001-arm64.msi.asc)|[OpenVPN-2.6.22-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.22-I001-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.22-I001-x86.msi.asc)|[OpenVPN-2.6.22-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.22-I001-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.22.tar.gz.asc)|[openvpn-2.6.22.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.22.tar.gz)|
+
+ For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
## OpenVPN 2.6.21 -- Released 1 July 2026
The OpenVPN community project team is proud to release OpenVPN 2.6.21. This is a bugfix release fixing
several security issues.
@@ 76,7 212,7 @@
|-|-|-|
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.21-I001-amd64.msi.asc)|[OpenVPN-2.6.21-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.21-I001-amd64.msi)|
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.21-I001-arm64.msi.asc)|[OpenVPN-2.6.21-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.21-I001-arm64.msi)|
- |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.20-I001-x86.msi.asc)|[OpenVPN-2.6.21-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.21-I001-x86.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.21-I001-x86.msi.asc)|[OpenVPN-2.6.21-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.21-I001-x86.msi)|
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.21.tar.gz.asc)|[openvpn-2.6.21.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.21.tar.gz)|
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9