Commit 2c3fb4

2026-10-07 12:29:30 flichtenheld: 2.7.8
ReleaseHistory.md ..
@@ 1,3 1,99 @@
+ ## OpenVPN 2.7.8 -- Released 7 October 2026
+ The OpenVPN community project team is proud to release OpenVPN 2.7.8. This is a bugfix release fixing
+ several security issues.
+
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7.8/Changes.rst)
+
+ Security fixes:
+
+ - Check for NULL-Bytes in certificate subjects - refuse all such certificates
+ now as "invalid" ([CVE-2026-84790](https://www.cve.org/CVERecord?id=CVE-2026-84790)).
+
+ (Bug reported by Vivek Parikh, tracked in
+ Github: OpenVPN/openvpn-private-issues#163)
+
+ - TLS handshake with tls-crypt-v2: do not try to add a wrapped client key
+ if no key material is available (client bug in response to an ill-behaving
+ server).
+
+ (No CVE assigned as "a malicious server can stop the client from working
+ properly" is not considered a CVE-worthy security issue according to the
+ CRA guidelines)
+
+ - options: fix unsigned underflow when clearing domain_search_list
+ ([CVE-2026-88964](https://www.cve.org/CVERecord?id=CVE-2026-84964))
+
+ (Bug reported and fix contributed by Cole Munz,
+ tracked in Github: OpenVPN/openvpn-private-issues#178)
+
+ - win32: stop cmd.exe from expanding variables in quoted arguments
+ ([CVE-2026-84256](https://www.cve.org/CVERecord?id=CVE-2026-84256))
+
+ (Bug reported by Darren Carreras, tracked in Github:
+ OpenVPN/openvpn-private-issues#176)
+
+ User-visible Changes:
+
+ - Certificate validation is now stricter regarding NULL bytes in strings
+ (see above). This might break existing installations if such certificates
+ exist and OpenSSL builds are used. mbedTLS builds always rejected this.
+
+ - On a certificate with duplicate fields (multiple CN, for example) OpenSSL
+ builds would use the last one, mbedTLS builds use the first one - changed
+ in the mbedTLS build so behaviour is identical.
+
+ Bugfixes:
+
+ - DCO: remove installed iroutes at client exit time, not at delayed
+ multi instance cleanup time - otherwise there is a race with reconnecting
+ clients, possibly ending up having "no iroutes installed in the system
+ at all". Bug reported by OpenVPN Inc Access Server team.
+
+ - DCO Linux: fix remaining races between synchronous netlink operations
+ and incoming asynchronous notifications, by adding a second netlink socket
+ and strictly separating sync/async operations.
+
+ - Client: refuse incoming pushed option combination of epoch data format
+ with non-AEAD ciphers (restart session instead of aborting with a fatal
+ error).
+
+ - DCO (Linux and Windows): on failures to set up a new peer or install
+ key materials for a peer, do not exit OpenVPN with a fatal error. Instead,
+ signal the error up the call-chain and restart the (multi) instance.
+
+ The handshake is inherently racy when a peer is removed kernel-side
+ due to transport errors or timeouts, and userland does not yet know this
+ and wants to, for example, install new keys. This is fatal for the
+ particular client instance, but must not end the whole server process.
+
+ - DCO: stop fetching peer stats during client disconnect
+ The intention of the original code was to ensure reported counters
+ are always correct, but it did not work (because at query time, the peer
+ in kernel is already gone, so we only got an error message) - and very
+ inefficiently so (because we queried all the peers all the time).
+ End-of-session final counter values will be implemented properly by a
+ followup patch leveraging counters piggybacked on the kernel's
+ "DEL_PEER" notification message.
+
+ - p2mp server: improve handling of mbuf lists in the face of broadcast
+ or multicast traffic, and fix a bug on client exit that could lead
+ to a server queue deadlock in very particular scenarios.
+
+ Windows MSI changes since 2.7.7-I001:
+ * Update included dco-win driver to v2.8.13
+ * [CVE-2026-105390](https://www.cve.org/CVERecord?id=CVE-2026-105390) — a locking flaw allowed a local user with access to the driver's device to cause a system deadlock and denial of service, hanging the host until it was power-cycled.
+ * Performance improvements by moving to multi-core data processing. See [Release Notes](https://github.com/OpenVPN/ovpn-dco-win/releases/tag/2.8.13) for details.
+ * Update included OpenSSL to 3.6.5
+
+ | | | |
+ |-|-|-|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.8-I001-amd64.msi.asc)|[OpenVPN-2.7.8-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.8-I001-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.8-I001-arm64.msi.asc)|[OpenVPN-2.7.8-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.8-I001-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.8-I001-x86.msi.asc)|[OpenVPN-2.7.8-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.8-I001-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7.8.tar.gz.asc)|[openvpn-2.7.8.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7.8.tar.gz)|
+
+ For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
+
## OpenVPN 2.6.23 -- Released 23 September 2026
The OpenVPN community project team is proud to release OpenVPN 2.6.23. This is a bugfix release fixing
several security issues.
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9