- dns: Fix memory leak in dns_server_addr_parse, if too many server
+
addresses are configured (Github: [OpenVPN/openvpn#1055](https://github.com/OpenVPN/openvpn/issues/1055))
+
+
- improve multi-socket event handling further - multiple open UDP sockets
+
with concurrent traffic could lead to inefficient processing, and the
+
old code was also very hard to follow.
+
+
(This was initially triggered by a report from Joshua Rogers using ZeroPath,
+
but turned out to be "just bad code" not a security vulnerability)
+
+
- Null-terminate tls-crypt client keys when testing - non-exploitable
+
strlen() on a buffer that is not null-terminated
+
+
- mudp: send HMAC reset reply synchronously
+
this fixes a bug where multiple incoming tls-crypt-v2 RESET packets
+
on different sockets could end up overwriting each other's control
+
structures, leading to initial handshake packets (HMAC reset reply)
+
being sent to the wrong client IP, or on a non-suitable socket
+
("v4 packet on a v6 socket"). Since the overall flow here is stateless
+
by nature, do not artificially create state by creating elaborate
+
queues, just send-or-drop.
+
+
- fix port-share and multi-socket interaction - port-share needs TCP
+
listeners, but the check was wrong. So "as long as any of the listening
+
sockets is TCP, port-share can be used" (Github: [OpenVPN/openvpn#1027](https://github.com/OpenVPN/openvpn/issues/1027))
+
+
- Ensure pushed tun-mtu is no lower than TUN_MTU_MIN - this fixes a bug
+
where a server can push a suitable combination of options and make the
+
client ASSERT().
+
+
(Reported as security issue by Haiyang Huang,
+
but it was decided that the server always has means to make the client
+
"not function properly", and it can not be exploited beyond that)
+
+
- Windows: socket: assert buffer length before reading prepended sockaddr
+
family - a misbehaviour in the windows DCO driver could trigger an
+
overread in the userland client. No such bug exists, which this was
+
not treated as a security vulnerability
+
+
Documentation improvements
+
--------------------------
+
- improve documentation for `--float` (Github: [OpenVPN/openvpn#358](https://github.com/OpenVPN/openvpn/issues/358))
+
- add documentation for `--preresolve` (Github: [OpenVPN/openvpn#532](https://github.com/OpenVPN/openvpn/issues/532))
+
- impove documentation around DNS config (Github: [OpenVPN/openvpn#937](https://github.com/OpenVPN/openvpn/issues/937))
-
* Included dco-win driver updated to 2.8.3
-
* [CVE-2026-11604](https://www.cve.org/CVERecord?id=CVE-2026-11604): An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win
-
allows a remote authenticated peer to trigger a heap-based buffer overflow and kernel memory corruption via a crafted data packet, resulting in a system crash