Commit 23ddda

2026-02-04 14:22:30 flichtenheld: 2.6.18
Downloads.md ..
@@ 50,36 50,46 @@
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
- ## OpenVPN 2.6.17 -- Released 28 November 2025
- The OpenVPN community project team is proud to release OpenVPN 2.6.17. This is a bugfix release containing one security fix.
-
- For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.17/Changes.rst)
-
- Security fixes:
-
- * [CVE-2025-13751](https://www.cve.org/CVERecord?id=CVE-2025-13751): Windows/interactive service: fix erroneous exit on error that could be
- used by a local Windows users to achieve a local denial-of-service
-
- Bug fixes:
-
- * Windows/interactive service: improve service pipe robustness against
- file access races (uuid) and access by unauthorized processes (ACL).
- * upgrade bundled build instruction (vcpkg and patch) for pkcs11-helper
- to 1.31, fixing a parser bug
-
- Windows MSI changes since 2.6.16-I001:
- * Built against OpenSSL 3.6.0
- * Included openvpn-gui updated to 11.59.0.0
- * Authorize config before opening the service pipe
- * Remove dependence on pathcch.dll not in Windows 7
- * Included win-dco driver updated to 2.8.0
-
+ ## OpenVPN 2.6.18 -- Released 4 February 2026
+ The OpenVPN community project team is proud to release OpenVPN 2.6.18. This is a bugfix release.
+
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.18/Changes.rst)
+
+ User visible changes:
+ * disable DCO if `--bind-dev` option is given (no support for this in
+ the old out-of-kernel Linux DCO implementation)
+ * on Windows, if using `--ip-win32 netsh` and not using the interactive
+ service, IPv4 addresses would be installed as "permanent", possibly
+ causing problems later on with using that IPv4 address on a different
+ interface. Change to "store=active". (GH: [#915](https://github.com/OpenVPN/openvpn/issues/915))
+ * improve pull-filter documentation, emphasizing possible problems if
+ used as a naive security measure (reported by SRLabs)
+
+ Bugfixes:
+ * p2mp server: fix incorrect file descriptor handling on "inotify" FD
+ during a SIGUSR1 restart (GH: [#966](https://github.com/OpenVPN/openvpn/issues/966))
+ * management interface: fix bug where `--management-forget-disconnect`
+ and `--management-signal` could be executed even if password authentication
+ to managment interface was still pending (ZeroPath finding)
+ * repair client-side interaction on reconnect between DCO event handling
+ and `--persist-tun` - after a ping timeout and reconnect, the DCO
+ event handler would not be armed, and the next ping timeout would not
+ be received by userland, causing non-working connections with nothing
+ in the openvpn log (Linux and FreeBSD only, GH: [#947](https://github.com/OpenVPN/openvpn/issues/947))
+ - prevent crash on invalid server-ipv6 argument, calling `freeaddrinfo()`
+ with a NULL pointer. This only affects OpenBSD. (Klemens Nanni).
+
+ Windows MSI changes since 2.6.17-I001:
+ * Built against OpenSSL 3.6.1
+ * Included openvpn-gui updated to 11.61.0.0
+ * translation updates
+
| | | |
|-|-|-|
- |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.17-I001-amd64.msi.asc)|[OpenVPN-2.6.17-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.17-I001-amd64.msi)|
- |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.17-I001-arm64.msi.asc)|[OpenVPN-2.6.17-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.17-I001-arm64.msi)|
- |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.17-I001-x86.msi.asc)|[OpenVPN-2.6.17-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.17-I001-x86.msi)|
- |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.17.tar.gz.asc)|[openvpn-2.6.17.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.17.tar.gz)|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.18-I001-amd64.msi.asc)|[OpenVPN-2.6.18-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.18-I001-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.18-I001-arm64.msi.asc)|[OpenVPN-2.6.18-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.18-I001-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.18-I001-x86.msi.asc)|[OpenVPN-2.6.18-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.18-I001-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.18.tar.gz.asc)|[openvpn-2.6.18.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.18.tar.gz)|
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9