(Bug reported by Darren Carreras, tracked in Github:
+
OpenVPN/openvpn-private-issues#176)
+
+
User-visible Changes:
+
+
- Certificate validation is now stricter regarding NULL bytes in strings
+
(see above). This might break existing installations if such certificates
+
exist and OpenSSL builds are used. mbedTLS builds always rejected this.
+
+
- On a certificate with duplicate fields (multiple CN, for example) OpenSSL
+
builds would use the last one, mbedTLS builds use the first one - changed
+
in the mbedTLS build so behaviour is identical.
+
+
Bugfixes:
+
+
- DCO: remove installed iroutes at client exit time, not at delayed
+
multi instance cleanup time - otherwise there is a race with reconnecting
+
clients, possibly ending up having "no iroutes installed in the system
+
at all". Bug reported by OpenVPN Inc Access Server team.
+
+
- DCO Linux: fix remaining races between synchronous netlink operations
+
and incoming asynchronous notifications, by adding a second netlink socket
+
and strictly separating sync/async operations.
+
+
- Client: refuse incoming pushed option combination of epoch data format
+
with non-AEAD ciphers (restart session instead of aborting with a fatal
+
error).
+
+
- DCO (Linux and Windows): on failures to set up a new peer or install
+
key materials for a peer, do not exit OpenVPN with a fatal error. Instead,
+
signal the error up the call-chain and restart the (multi) instance.
+
+
The handshake is inherently racy when a peer is removed kernel-side
+
due to transport errors or timeouts, and userland does not yet know this
+
and wants to, for example, install new keys. This is fatal for the
+
particular client instance, but must not end the whole server process.
+
+
- DCO: stop fetching peer stats during client disconnect
+
The intention of the original code was to ensure reported counters
+
are always correct, but it did not work (because at query time, the peer
+
in kernel is already gone, so we only got an error message) - and very
+
inefficiently so (because we queried all the peers all the time).
+
End-of-session final counter values will be implemented properly by a
+
followup patch leveraging counters piggybacked on the kernel's
+
"DEL_PEER" notification message.
+
+
- p2mp server: improve handling of mbuf lists in the face of broadcast
+
or multicast traffic, and fix a bug on client exit that could lead
+
to a server queue deadlock in very particular scenarios.
+
+
Windows MSI changes since 2.7.7-I001:
+
* Update included dco-win driver to v2.8.13
+
* [CVE-2026-105390](https://www.cve.org/CVERecord?id=CVE-2026-105390) — a locking flaw allowed a local user with access to the driver's device to cause a system deadlock and denial of service, hanging the host until it was power-cycled.
+
* Performance improvements by moving to multi-core data processing. See [Release Notes](https://github.com/OpenVPN/ovpn-dco-win/releases/tag/2.8.13) for details.