Commit 39396b

2026-07-01 13:37:52 flichtenheld: 2.7.5
Downloads.md ..
@@ 1,38 1,127 @@
- ## OpenVPN 2.7.4 -- Released 30 April 2026
- The OpenVPN community project team is proud to release OpenVPN 2.7.4. This is a small bugfix release.
+ ## OpenVPN 2.7.5 -- Released 1 July 2026
+ The OpenVPN community project team is proud to release OpenVPN 2.7.5. This is a bugfix release fixing
+ several security issues.
- For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7.4/Changes.rst)
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7.5/Changes.rst)
- Bugfixes:
+ Security fixes:
+
+ - openvpnserv (windows): fix DNS SearchList state pollution on (dis)connect.
+ specific combinations of `--dns` config entries plus local DNS config
+ could lead to corruption of pre-openvpn DNS config ([CVE-2026-13379](https://www.cve.org/CVERecord?id=CVE-2026-13379))
+
+ Bug found by 章鱼哥 (www.aipyaipy.com).
+
+ - Fix use-after-free bug in ack_write_buf(), triggerable by a well-timed
+ sequence of control channel + authentication packets ([CVE-2026-12996](https://www.cve.org/CVERecord?id=CVE-2026-12996))
+
+ Bug found by multiple researchers:
+ - 章鱼哥 (www.aipyaipy.com)
+ - Haiyang Huang
+ - Haruki Oyama (Waseda University)
+
+ - Fix use-after-free bug in tls_wrap_reneg(), triggerable by suitable
+ sequence of dynamic tls-crypt control-channel packets ([CVE-2026-13117](https://www.cve.org/CVERecord?id=CVE-2026-13117))
+
+ Bug found by multiple researchers:
+ - Trace37 Labs (github.com/trace37labs)
+ - Haiyang Huang
+
+ - Fix server crash on reception of suitably malformed auth-token, if
+ `--auth-gen-token external-auth` is active ([CVE-2026-13122](https://www.cve.org/CVERecord?id=CVE-2026-13122))
+
+ Bug found by Haiyang Huang.
+
+ - Fix memory-leak in tls-crypt-v2 client key handling that could lead
+ to out-of-memory situations and subsequent server crashes ([CVE-2026-12932](https://www.cve.org/CVERecord?id=CVE-2026-12932))
+
+ Bug found by Valton Tahiri.
+
+ - Fix possible 1-byte buffer overrun on NTLMv2 proxy responses.
+ ([CVE-2026-11771](https://www.cve.org/CVERecord?id=CVE-2026-11771))
+
+ Bug found by Tristan Madani (@TristanInSec).
- - using `--dns server ...` style configs on Windows with win-dco would
- lead to erroneously enabling "DnsSecValidationRequired : True", possibly
- breaking VPN DNS resolution. Pushing `--dns server ... dnssec no`
- can be used as a workaround until clients can be updated.
- (Github: [openvpn#1024](https://github.com/OpenVPN/openvpn/issues/1024))
- - correct comments in the `--dns-up-down` platform scripts relating to
- `dns_server_..._dnssec` values.
- - fix release-only build of pkcs11-helper vcpkg port, do not try to
- install files from debug build.
- - mbedTLS builds will now provide a proper error message if a
- `tls-group` statement with no valid groups is encountered
- (used to run into SSL handshake failure later on).
- - `--enable-strict` and `--enable-strict-options` configure flags have
- been removed (because they did not actually do anything anymore)
+ - Fix another memory leak on reception of suitable tls-crypt-v2 packets
+ that could lead to an out of memory situation and server crash
+ ([CVE-2026-13698](https://www.cve.org/CVERecord?id=CVE-2026-13698))
- Note: Windows MSI was updated to I002 on June 10th. Changes in I002:
+ Bug found by Max Fillinger. Overlaps with a report
+ from Valton Tahiri that we believe to
+ be fixed by this bugfix as well.
+
+ Bugfixes
+ --------
+ - Windows: fix plugin trusted-dir check prefix bypass
+ (this fixes a bug in the path checking logic we do on Windows for
+ "is loading a plugin from this path allowed?", but since we could
+ not find a way to exploit this unless starting with admin privs or
+ a social engineering attack, not classified as a security fix)
+
+ - Windows: openvpnserv: rework ConvertItfDnsDomains and tests
+ (this fixes a buffer overread that is not exploitable and as such
+ not classified as security fix)
+
+ - options: fix use-after-free of DNS options on client connect
+ (using suitable `--dns` or `--dhcp-option DNS` options in a server
+ config - not pushed, but applying to the server itself - triggers a
+ double free() and use-after-free condition, possibly crashing the
+ server) (Github: [OpenVPN/openvpn#1060](https://github.com/OpenVPN/openvpn/issues/1060))
+
+ - dns: Fix memory leak in dns_server_addr_parse, if too many server
+ addresses are configured (Github: [OpenVPN/openvpn#1055](https://github.com/OpenVPN/openvpn/issues/1055))
+
+ - improve multi-socket event handling further - multiple open UDP sockets
+ with concurrent traffic could lead to inefficient processing, and the
+ old code was also very hard to follow.
+
+ (This was initially triggered by a report from Joshua Rogers using ZeroPath,
+ but turned out to be "just bad code" not a security vulnerability)
+
+ - Null-terminate tls-crypt client keys when testing - non-exploitable
+ strlen() on a buffer that is not null-terminated
+
+ - mudp: send HMAC reset reply synchronously
+ this fixes a bug where multiple incoming tls-crypt-v2 RESET packets
+ on different sockets could end up overwriting each other's control
+ structures, leading to initial handshake packets (HMAC reset reply)
+ being sent to the wrong client IP, or on a non-suitable socket
+ ("v4 packet on a v6 socket"). Since the overall flow here is stateless
+ by nature, do not artificially create state by creating elaborate
+ queues, just send-or-drop.
+
+ - fix port-share and multi-socket interaction - port-share needs TCP
+ listeners, but the check was wrong. So "as long as any of the listening
+ sockets is TCP, port-share can be used" (Github: [OpenVPN/openvpn#1027](https://github.com/OpenVPN/openvpn/issues/1027))
+
+ - Ensure pushed tun-mtu is no lower than TUN_MTU_MIN - this fixes a bug
+ where a server can push a suitable combination of options and make the
+ client ASSERT().
+
+ (Reported as security issue by Haiyang Huang,
+ but it was decided that the server always has means to make the client
+ "not function properly", and it can not be exploited beyond that)
+
+ - Windows: socket: assert buffer length before reading prepended sockaddr
+ family - a misbehaviour in the windows DCO driver could trigger an
+ overread in the userland client. No such bug exists, which this was
+ not treated as a security vulnerability
+
+ Documentation improvements
+ --------------------------
+ - improve documentation for `--float` (Github: [OpenVPN/openvpn#358](https://github.com/OpenVPN/openvpn/issues/358))
+ - add documentation for `--preresolve` (Github: [OpenVPN/openvpn#532](https://github.com/OpenVPN/openvpn/issues/532))
+ - impove documentation around DNS config (Github: [OpenVPN/openvpn#937](https://github.com/OpenVPN/openvpn/issues/937))
- * Included dco-win driver updated to 2.8.3
- * [CVE-2026-11604](https://www.cve.org/CVERecord?id=CVE-2026-11604): An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win
- allows a remote authenticated peer to trigger a heap-based buffer overflow and kernel memory corruption via a crafted data packet, resulting in a system crash
- (denial of service).
+ Windows MSI changes since 2.7.4-I002:
+ * Built against OpenSSL 3.6.3
| | | |
|-|-|-|
- |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.4-I002-amd64.msi.asc)|[OpenVPN-2.7.4-I002-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.4-I002-amd64.msi)|
- |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.4-I002-arm64.msi.asc)|[OpenVPN-2.7.4-I002-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.4-I002-arm64.msi)|
- |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.4-I002-x86.msi.asc)|[OpenVPN-2.7.4-I002-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.4-I002-x86.msi)|
- |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7.4.tar.gz.asc)|[openvpn-2.7.4.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7.4.tar.gz)|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.5-I001-amd64.msi.asc)|[OpenVPN-2.7.5-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.5-I001-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.5-I001-arm64.msi.asc)|[OpenVPN-2.7.5-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.5-I001-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.5-I001-x86.msi.asc)|[OpenVPN-2.7.5-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.5-I001-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7.5.tar.gz.asc)|[openvpn-2.7.5.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7.5.tar.gz)|
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9