For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
-
## OpenVPN 2.6.15 -- Released 22 September 2025
-
The OpenVPN community project team is proud to release OpenVPN 2.6.15. This is a bugfix release.
+
## OpenVPN 2.6.16 -- Released 17 November 2025
+
The OpenVPN community project team is proud to release OpenVPN 2.6.16. This is a bugfix release containing one security fix.
-
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.15/Changes.rst)
+
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.16/Changes.rst)
+
+
Security fixes:
+
+
* [CVE-2025-13086](https://www.cve.org/CVERecord?id=CVE-2025-13086): Fix memcmp check for the hmac verification in the 3way handshake.
+
This bug renders the HMAC based protection against state exhaustion on
+
receiving spoofed TLS handshake packets in the OpenVPN server inefficient.
Bug fixes:
-
* On Windows, do not use "wmic.exe" any longer to set DNS search domain
-
(discontinued by Microsoft), use "powershell" fragment instead.
-
* On Windows, logging to the windows event log has been improved
-
(and logging of GetLastError() strings repaired). To make this work,
-
a new "openvpnmsgserv.dll" library is now installed and registered.
-
* DNS domain names are now strictly validated with a positive-list of
-
allowed characters (including UTF-8 high-bit-set bytes) before being
-
handed to powershell.
-
* Apply more checks to incoming TLS handshake packets before creating
-
new state - namely, verify message ID / acked ID for "valid range for
-
an initial packet". This fixes a problem with clients that float
-
very early but send control channel packet from the pre-float IP