Commit 162ced

2025-11-17 17:59:58 uddr: OpenVPN-2.6.16-I001
Downloads.md ..
@@ 79,48 79,56 @@
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
- ## OpenVPN 2.6.15 -- Released 22 September 2025
- The OpenVPN community project team is proud to release OpenVPN 2.6.15. This is a bugfix release.
+ ## OpenVPN 2.6.16 -- Released 17 November 2025
+ The OpenVPN community project team is proud to release OpenVPN 2.6.16. This is a bugfix release containing one security fix.
- For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.15/Changes.rst)
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.16/Changes.rst)
+
+ Security fixes:
+
+ * [CVE-2025-13086](https://www.cve.org/CVERecord?id=CVE-2025-13086): Fix memcmp check for the hmac verification in the 3way handshake.
+ This bug renders the HMAC based protection against state exhaustion on
+ receiving spoofed TLS handshake packets in the OpenVPN server inefficient.
Bug fixes:
- * On Windows, do not use "wmic.exe" any longer to set DNS search domain
- (discontinued by Microsoft), use "powershell" fragment instead.
- * On Windows, logging to the windows event log has been improved
- (and logging of GetLastError() strings repaired). To make this work,
- a new "openvpnmsgserv.dll" library is now installed and registered.
- * DNS domain names are now strictly validated with a positive-list of
- allowed characters (including UTF-8 high-bit-set bytes) before being
- handed to powershell.
- * Apply more checks to incoming TLS handshake packets before creating
- new state - namely, verify message ID / acked ID for "valid range for
- an initial packet". This fixes a problem with clients that float
- very early but send control channel packet from the pre-float IP
- (Github: [OpenVPN/openvpn#704](https://github.com/OpenVPN/openvpn/issues/704),
- backported from 2.7_beta1).
- * Backport handling of client float notifications on FreeBSD 14/STABLE DCO
- (see https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=289303)
- * Update GPL license text to latest version from FSF
- * On Linux, on interfaces where applicable, OpenVPN explicitly configures
- the broadcast address again. This was dropped for 2.6.0 "because
- computers are smart and can do it themselves", but the kernel netlink
- interface isn't, and will install "0.0.0.0". This does not normally
- matter, but for broadcast-based applications that get the address to
- use from "ifconfig", this change repairs functionality.
-
- Windows MSI changes since 2.6.14-I004:
- * Built against OpenSSL 3.5.3
- * Included openvpn-gui updated to 11.56.0.0
- * Fix "Cannot open the System Tray Menu with Keyboard" (Github: [OpenVPN/openvpn-gui#763](https://github.com/OpenVPN/openvpn-gui/issues/763))
+ * fix invalid pointer creation in tls_pre_decrypt() - technically this is
+ a memory over-read issue, in practice, the compilers optimize it away
+ so no negative effects could be observed.
+ * Windows: in the interactive service, fix the "undo DNS config" handling.
+ * Windows: in the interactive service, disallow using of "stdin" for the
+ config file, unless the caller is authorized OpenVPN Administrator
+ * Windows: in the interactive service, change all netsh calls to use
+ interface index and not interface name - sidesteps all possible attack
+ avenues with special characters in interface names.
+ * Windows: in the interactive service, improve error handling in
+ some "unlikely to happen" paths.
+ * auth plugin/script handling: properly check for errors in creation on
+ $auth_failed_reason_file (arf).
+ * for incoming TCP connections, close-on-exec option was applied to
+ the wrong socket fd, leaking socket FDs to child processes.
+ * sitnl: set close-on-exec flag on netlink socket
+ * ssl_mbedtls: fix missing perf_pop() call (optional performance profiling)
+
+ Windows MSI changes since 2.6.15-I001:
+ * Built against OpenSSL 3.6.0
+ * Included openvpn-gui updated to 11.58.0.0
+ * Check the return value of GetProp()
+ * Make config path check similar to that in interactive service
+ * Escape the type id of password message received from openvpn
+ * Add a message source for event logging
+ * Check correct management daemon path when OpenVPN3 is enabled
+ * Fix OpenVPN3 radio button label size when OVPN3 is enabled
+ * Use GetTempPath() for debug file in plap as well
+ * Migrate all saved plain usernames to encrypted format
+ * Included win-dco driver updated to 2.8.0
| | | |
|-|-|-|
- |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.15-I001-amd64.msi.asc)|[OpenVPN-2.6.15-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.15-I001-amd64.msi)|
- |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.15-I001-arm64.msi.asc)|[OpenVPN-2.6.15-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.15-I001-arm64.msi)|
- |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.15-I001-x86.msi.asc)|[OpenVPN-2.6.15-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.15-I001-x86.msi)|
- |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.15.tar.gz.asc)|[openvpn-2.6.15.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.15.tar.gz)|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.16-I001-amd64.msi.asc)|[OpenVPN-2.6.16-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.16-I001-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.16-I001-arm64.msi.asc)|[OpenVPN-2.6.16-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.16-I001-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.16-I001-x86.msi.asc)|[OpenVPN-2.6.16-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.16-I001-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.16.tar.gz.asc)|[openvpn-2.6.16.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.16.tar.gz)|
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9