Commit 30bd51

2026-09-23 14:18:40 uddr: 2.6.23
Downloads.md ..
@@ 126,59 126,73 @@
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
- ## OpenVPN 2.6.22 -- Released 5 August 2026
- The OpenVPN community project team is proud to release OpenVPN 2.6.22. This is a bugfix release fixing
+ ## OpenVPN 2.6.23 -- Released 23 September 2026
+ The OpenVPN community project team is proud to release OpenVPN 2.6.23. This is a bugfix release fixing
several security issues.
> [!IMPORTANT]
- > After this release the [support status](../Pages/Supported%20versions) of OpenVPN 2.6 changes from "Full Support" to "Old Stable Support"
+ > After 2.6.22 release the [support status](../Pages/Supported%20versions) of OpenVPN 2.6 changes from "Full Support" to "Old Stable Support"
> This means that we might not provide Windows installer downloads of future 2.6.x releases. Please upgrade to OpenVPN 2.7.
- For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.22/Changes.rst)
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.23/Changes.rst)
Security fixes:
- - openvpnserv (windows): better scrutinize command line passed in
- from the control socket to openvpn. This would lead to circumventing
- admin restrictions on allowed openvpn config directories (but never
- to "read files the user has no permissions for") ([CVE-2026-63649](https://www.cve.org/CVERecord?id=CVE-2026-63649))
+ - ssl: do not trust the peer's request to resend the wrapped client key
- Bug found by 章鱼哥 (www.aipyaipy.com)
+ Tracked in Github: OpenVPN/openvpn-private-issues#181
- - dco: make key state desync recoverable
+ - reliability layer: avoid unbounded reliable TLS timeout, and ignore acks
+ for packets that cannot be outstanding ([CVE-2026-84732](https://www.cve.org/CVERecord?id=CVE-2026-84732))
- This was reported as a "with suitable timing, a key-update de-sync between
- OpenVPN and the kernel could trigger an ASSERT()", and was initially
- handled as security report. It turned out to be not exploitable, but the
- state machine was not very robust and so the opportunity was used to
- improve the code.
+ Both reliability layer bugs found by Mark Bregman (Fox-IT), tracked in
+ Github: OpenVPN/openvpn-private-issues#161
- Bug found by 章鱼哥 (www.aipyaipy.com)
+ - improve on `check_session_buf_not_used()`, catch possible double-free in
+ the lame duck case ([CVE-2026-84471](https://www.cve.org/CVERecord?id=CVE-2026-84471))
- Bugfixes:
+ Bug reported by Andreas Gabriel Berbescu, tracked in Github:
+ OpenVPN/openvpn-private-issues#157, and by Haruki Oyama (Waseda
+ University), tracked in OpenVPN/openvpn-private-issues#132
- - refuse incoming HARD RESET packets with a sequence ID != 0
- (this is basically making an OpenVPN server ignore and log a
- "should never happen" client-side misbehaviour, which could lead to
- TLS handshake establishment failures in p2p TLS setups)
+ - windows: fix `CreateProcess()` command line quoting for characters that
+ are special to `cmd.exe`, where a combination of validation script plus
+ rogue CA could lead to misbehavior ([CVE-2026-84256](https://www.cve.org/CVERecord?id=CVE-2026-84256))
- - correct minimum packet length check for 802.1q tagged packets
- (Github: [OpenVPN/openvpn#1044](https://github.com/OpenVPN/openvpn/issues/1044)).
+ Bug found by Clouditera Security, tracked in Github:
+ OpenVPN/openvpn-private-issues#159
- This was also reported (twice) as a security bug, as technically
- OpenVPN with `--client-nat` would read and write up to 4 bytes
- "after the end of the packet" - but due to the OpenVPN packet buffer
- layouts, which are always full-frame-sized this is fully safe and has
- no adverse consequences.
+ - windows: fix `tapctl` to always call `netsh.exe` with full path
+ (as we do elsewhere) ([CVE-2026-84226](https://www.cve.org/CVERecord?id=CVE-2026-84226))
+ Bug found by BreachX Zero Day Labs (using Typhon AI Mil v2), tracked in
+ Github: OpenVPN/openvpn-private-issues#164
+
+ - windows: don't use NULL DACL with system objects, namely the `--service`
+ exit event and the `netsh.exe` guard semaphore. The old approach was
+ prone to a local DoS where one user could interfere with other users'
+ openvpn processes by blocking the netsh semaphore or sending events.
+ This only affects setups not using the iservice, or using the automatic
+ service to start/stop openvpn ([CVE-2026-82312](https://www.cve.org/CVERecord?id=CVE-2026-82312))
+
+ Bug found by DEBRAJ BASAK, tracked in Github:
+ OpenVPN/openvpn-private-issues#167
+
+ - dhcp (windows): fix off-by-one in `write_dhcp_search_str()` temp buffer
+ guard - suitable DHCP options could lead to a single-byte overflow of a
+ temp buffer ([CVE-2026-81738](https://www.cve.org/CVERecord?id=CVE-2026-81738))
+
+ Bug found by Andre Kropp (Nexory) and ChinhNguyen, tracked in Github:
+ OpenVPN/openvpn-private-issues#165
+
+ - openvpnserv (windows): detect and refuse sibling dirs in
+ `CheckConfigPath()` ([CVE-2026-81830](https://www.cve.org/CVERecord?id=CVE-2026-81830))
+
+ Bug found by Harshit Varu, tracked in Github:
+ OpenVPN/openvpn-private-issues#166
| | | |
|-|-|-|
- |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.22-I001-amd64.msi.asc)|[OpenVPN-2.6.22-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.22-I001-amd64.msi)|
- |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.22-I001-arm64.msi.asc)|[OpenVPN-2.6.22-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.22-I001-arm64.msi)|
- |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.22-I001-x86.msi.asc)|[OpenVPN-2.6.22-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.22-I001-x86.msi)|
- |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.22.tar.gz.asc)|[openvpn-2.6.22.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.22.tar.gz)|
-
- For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.23.tar.gz.asc)|[openvpn-2.6.23.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.23.tar.gz)|
#### [Full Release History](https://community.openvpn.net/ReleaseHistory)
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9