2025-11-28 18:07:25uddr:
2.6.17 and 2.7_rc3 releases
ReleaseHistory.md ..
@@ 1,3 1,121 @@
+
## OpenVPN 2.7_rc3 -- Released 28 November 2025
+
The OpenVPN community project team is proud to release OpenVPN 2.7_rc3. This is the third release candidate for the feature release 2.7.0.
+
+
Security fixes:
+
* [CVE-2025-13751](https://www.cve.org/CVERecord?id=CVE-2025-13751): Windows/interactive service: fix bug where the interactive service would error-exit in
+
certain error conditions instead of just logging the fact and
+
continuing. After the error-exit, OpenVPN connections will no
+
longer work until the service is restarted (or the system rebooted).
+
This can be triggered by any authenticated local user, and has
+
thus been classified as a "local denial of service" attack.
+
+
Important bug fixes since 2.7_rc2:
+
* Windows/Interactive Service bugfixes:
+
many small bugfixes to registry-related DNS domain handling
+
* Windows/Interactive Service: harden service pipe handling
+
close a small race condition, and add restrictive ACLs
+
* more type conversion related warnings have been fixed
+
* --multihome behaviour regarding egress interface selection has been
+
changed. See Changes.rst and manpage for details.
+
* cleanup dead code in event handling code (leftover of the multisocket
+
patch set)
+
* add new feature, --tls-crypt-v2-max-age n. See Changes.rst and
+
manpage for details.
+
* improve documentation to point out the pitfalls of case-insensitive
+
filesystems and --client-config-dir
+
* split default gateway query logic in two:
+
* for --redirect-gateway functionality, query for the gateway towards
+
the actual IP address of the VPN server connecting to
+
* for the "net_gateway" special destination for --route, and the
+
corresponding environment variable, always query for 0.0.0.0 / ::
+
(this will only make a difference in certain scenarios using a local
+
proxy, or on a system with multiple interfaces, not using the "default
+
route" for the VPN connection * see github#890)
+
* upgrade embedded pkcs11-helper vcpkg + pkcs11-uri patch to 1.31
* DCO (primarily Linux): improve handling of bulk notifications from
+
kernel (do not lose notifications, do not crash) ([github#900](https://github.com/OpenVPN/openvpn/issues/900))
+
+
For a list of all changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_rc2...v2.7_rc3).
+
+
Highlights of 2.7 include:
+
* Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
+
* Improved Client support for DNS options
+
* Client implementations for Linux/BSD/macOS, included with the default install
+
* New client implementation for Windows, adding support for features like split DNS and DNSSEC
+
* Architectural improvements on Windows
+
* The `block-local` flag is now enforced with WFP filters
+
* Windows network adapters are now generated on demand
+
* Windows automatic service now runs as an unpriviledged user
+
* Support for server mode in win-dco driver
+
* Note: Support for the wintun driver has been removed. win-dco is now the default, tap-windows6 is the fallback solution for use-cases not covered by win-dco.
+
* Improved data channel
+
* Enforcement of AES-GCM usage limit
+
* Epoch data keys and packet format
+
* Support for new upstream DCO Linux kernel module
+
* This release supports the new `ovpn` DCO Linux kernel module which will be available in future upstream Linux kernel releases. Backports of the new module to current kernels are available via the [ovpn-backports project](https://github.com/OpenVPN/ovpn-backports).
+
* Client-side support for new `PUSH_UPDATE` control-channel message
+
* This allows servers to send updates to options like routing and DNS config without triggering a reconnect.
+
* PUSH_UPDATE server support (minimal)
+
* New management interface commands `push-update-broad` and `push-update-cid` to send PUSH_UPDATE option updates.
+
* TLS 1.3 support with bleeding-edge mbedTLS versions
+
* Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
+
* Support for Epoch data channel on Windows, using the win-dco driver (2.8.0+)
+
* "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
+
* COPYING: license details only relevant to our Windows installers have been updated and moved to the openvpn-build repo
+
+
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_rc3/Changes.rst)
+
+
Windows MSI changes since 2.7_rc2:
+
* Built against OpenSSL 3.6.0
+
* Included openvpn-gui updated to 11.59.0.0
+
* Authorize config before opening the service pipe
+
* Remove dependence on pathcch.dll not in Windows 7
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
+
+
## OpenVPN 2.6.17 -- Released 28 November 2025
+
The OpenVPN community project team is proud to release OpenVPN 2.6.17. This is a bugfix release containing one security fix.
+
+
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.17/Changes.rst)
+
+
Security fixes:
+
+
* [CVE-2025-13751](https://www.cve.org/CVERecord?id=CVE-2025-13751): Windows/interactive service: fix erroneous exit on error that could be
+
used by a local Windows users to achieve a local denial-of-service
+
+
Bug fixes:
+
+
* Windows/interactive service: improve service pipe robustness against
+
file access races (uuid) and access by unauthorized processes (ACL).
+
* upgrade bundled build instruction (vcpkg and patch) for pkcs11-helper
+
to 1.31, fixing a parser bug
+
+
Windows MSI changes since 2.6.16-I001:
+
* Built against OpenSSL 3.6.0
+
* Included openvpn-gui updated to 11.59.0.0
+
* Authorize config before opening the service pipe
+
* Remove dependence on pathcch.dll not in Windows 7