Commit 4293c2

2025-11-17 18:01:55 uddr: OpenVPN-2.7_rc2-I009 and OpenVPN-2.6.16-I001
ReleaseHistory.md ..
@@ 1,3 1,137 @@
+ ## OpenVPN 2.7_rc2 -- Released 17 November 2025
+ The OpenVPN community project team is proud to release OpenVPN 2.7_rc2. This is the second release candidate for the feature release 2.7.0.
+
+ Security fixes:
+ * [CVE-2025-12106](https://www.cve.org/CVERecord?id=CVE-2025-12106): IPv6 address parsing: fix buffer overread on invalid input
+ * [CVE-2025-13086](https://www.cve.org/CVERecord?id=CVE-2025-13086): HMAC verification check: fix incorrect memcmp() call
+
+ Important bug fixes since 2.7_rc1:
+ * even more type conversion related warnings have been fixed
+ * DCO FreeBSD improvements:
+ * improving debug messages (verb 6)
+ * implement client-side counter handling
+ * repair --inactive (and document shortcomings)
+ * repair handling of DCO disconnection notifications in --client mode
+ * Windows/Service improvements, hardening, bugfixes
+ * fix DNS address list generation (if 3 or more --dns addresses in use)
+ * fix DNS server undo_list
+ * disallow "stdin" as config name unless user has OpenVPN admin privs
+ * fix compilation errors with MSVC v19
+ * iservice: improve validation of config path (pathcc lib)
+ * [NOTE: this breaks OpenVPN compatibility with Windows 7]
+ * tapctl: refactor, improve output, change driver default to ovpn-dco
+ * iservice: when restoring iface metrics, enforce correct ifindex
+ * improve cmocka unit test assert() handling
+ * PUSH_UPDATE server: fix reporting of client IPs in ``status`` output after pushing a new IPv4/IPv6 address to client
+ * AEAD cipher safety margins: fix calculation of AEAD blocks in use (old code would undercount blocks)
+ * fix invalid pointer creation / memory overread in tls_pre_decrypt
+ * deprecate ``--opt-verify`` (change into no-op + warning)
+
+ For a list of all changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_rc1...v2.7_rc2).
+
+ Highlights of 2.7 include:
+ * Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
+ * Improved Client support for DNS options
+ * Client implementations for Linux/BSD/macOS, included with the default install
+ * New client implementation for Windows, adding support for features like split DNS and DNSSEC
+ * Architectural improvements on Windows
+ * The `block-local` flag is now enforced with WFP filters
+ * Windows network adapters are now generated on demand
+ * Windows automatic service now runs as an unpriviledged user
+ * Support for server mode in win-dco driver
+ * Note: Support for the wintun driver has been removed. win-dco is now the default, tap-windows6 is the fallback solution for use-cases not covered by win-dco.
+ * Improved data channel
+ * Enforcement of AES-GCM usage limit
+ * Epoch data keys and packet format
+ * Support for new upstream DCO Linux kernel module
+ * This release supports the new `ovpn` DCO Linux kernel module which will be available in future upstream Linux kernel releases. Backports of the new module to current kernels are available via the [ovpn-backports project](https://github.com/OpenVPN/ovpn-backports).
+ * Client-side support for new `PUSH_UPDATE` control-channel message
+ * This allows servers to send updates to options like routing and DNS config without triggering a reconnect.
+ * PUSH_UPDATE server support (minimal)
+ * New management interface commands `push-update-broad` and `push-update-cid` to send PUSH_UPDATE option updates.
+ * TLS 1.3 support with bleeding-edge mbedTLS versions
+ * Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
+ * Support for Epoch data channel on Windows, using the win-dco driver (2.8.0+)
+ * "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
+ * COPYING: license details only relevant to our Windows installers have been updated and moved to the openvpn-build repo
+
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_rc2/Changes.rst)
+
+ Windows MSI changes since 2.7_rc1:
+ * Built against OpenSSL 3.6.0
+ * Included openvpn-gui updated to 11.58.0.0
+ * Check the return value of GetProp()
+ * Make config path check similar to that in interactive service
+ * Escape the type id of password message received from openvpn
+ * Add a message source for event logging
+ * Check correct management daemon path when OpenVPN3 is enabled
+ * Fix OpenVPN3 radio button label size when OVPN3 is enabled
+ * Use GetTempPath() for debug file in plap as well
+ * Migrate all saved plain usernames to encrypted format
+ * Included win-dco driver updated to 2.8.0
+
+ | | | |
+ |-|-|-|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc2-I009-amd64.msi.asc)|[OpenVPN-2.7_rc2-I009-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc2-I009-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc2-I009-arm64.msi.asc)|[OpenVPN-2.7_rc2-I009-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc2-I009-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc2-I009-x86.msi.asc)|[OpenVPN-2.7_rc2-I009-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc2-I009-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc2.tar.gz.asc)|[openvpn-2.7_rc2.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc2.tar.gz)|
+
+ For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
+
+ ## OpenVPN 2.6.16 -- Released 17 November 2025
+ The OpenVPN community project team is proud to release OpenVPN 2.6.16. This is a bugfix release containing one security fix.
+
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.16/Changes.rst)
+
+ Security fixes:
+
+ * [CVE-2025-13086](https://www.cve.org/CVERecord?id=CVE-2025-13086): Fix memcmp check for the hmac verification in the 3way handshake.
+ This bug renders the HMAC based protection against state exhaustion on
+ receiving spoofed TLS handshake packets in the OpenVPN server inefficient.
+
+ Bug fixes:
+
+ * fix invalid pointer creation in tls_pre_decrypt() - technically this is
+ a memory over-read issue, in practice, the compilers optimize it away
+ so no negative effects could be observed.
+ * Windows: in the interactive service, fix the "undo DNS config" handling.
+ * Windows: in the interactive service, disallow using of "stdin" for the
+ config file, unless the caller is authorized OpenVPN Administrator
+ * Windows: in the interactive service, change all netsh calls to use
+ interface index and not interface name - sidesteps all possible attack
+ avenues with special characters in interface names.
+ * Windows: in the interactive service, improve error handling in
+ some "unlikely to happen" paths.
+ * auth plugin/script handling: properly check for errors in creation on
+ $auth_failed_reason_file (arf).
+ * for incoming TCP connections, close-on-exec option was applied to
+ the wrong socket fd, leaking socket FDs to child processes.
+ * sitnl: set close-on-exec flag on netlink socket
+ * ssl_mbedtls: fix missing perf_pop() call (optional performance profiling)
+
+ Windows MSI changes since 2.6.15-I001:
+ * Built against OpenSSL 3.6.0
+ * Included openvpn-gui updated to 11.58.0.0
+ * Check the return value of GetProp()
+ * Make config path check similar to that in interactive service
+ * Escape the type id of password message received from openvpn
+ * Add a message source for event logging
+ * Check correct management daemon path when OpenVPN3 is enabled
+ * Fix OpenVPN3 radio button label size when OVPN3 is enabled
+ * Use GetTempPath() for debug file in plap as well
+ * Migrate all saved plain usernames to encrypted format
+ * Included win-dco driver updated to 2.8.0
+
+ | | | |
+ |-|-|-|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.16-I001-amd64.msi.asc)|[OpenVPN-2.6.16-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.16-I001-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.16-I001-arm64.msi.asc)|[OpenVPN-2.6.16-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.16-I001-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.16-I001-x86.msi.asc)|[OpenVPN-2.6.16-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.16-I001-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.16.tar.gz.asc)|[openvpn-2.6.16.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.16.tar.gz)|
+
+ For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
+
## OpenVPN 2.7_rc1 -- Released 31 October 2025
The OpenVPN community project team is proud to release OpenVPN 2.7_rc1. This is the first release candidate for the feature release 2.7.0.
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9