Commit 4b4a8b

2025-06-20 13:43:39 uddr: new download page
/dev/null .. Downloads.md
@@ 0,0 1,78 @@
+ ## OpenVPN 2.6.14 -- Released 02 April 2025
+ The OpenVPN community project team is proud to release OpenVPN 2.6.14. This is a bugfix release containing one security fix.
+
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.14/Changes.rst)
+
+ Security fixes:
+
+ * [CVE-2025-2704](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-2704): fix possible `ASSERT()` on OpenVPN servers using `--tls-crypt-v2`
+ Security scope: OpenVPN servers between 2.6.1 and 2.6.13 using
+ `--tls-crypt-v2` can be made to abort with an `ASSERT()` message by
+ sending a particular combination of authenticated and malformed packets.
+ To trigger the bug, a valid tls-crypt-v2 client key is needed, or
+ network observation of a handshake with a valid tls-crypt-v2 client key.
+ No crypto integrity is violated, no data is leaked, and no remote
+ code execution is possible.
+ This bug does not affect OpenVPN clients.
+ (Bug found by internal QA at OpenVPN Inc)
+
+ Bug fixes:
+
+ * Linux DCO: repair source IP selection for `--multihome` (Qingfang Deng)
+
+ Windows MSI changes since 2.6.13:
+ * Built against OpenSSL 3.4.1
+ * Included openvpn-gui updated to 11.52.0.0
+ * Use correct `%TEMP%` directory for debug log file.
+ * Disable config in menu listing if its ovpn file becomes inaccessible (github [openvpn-gui#729](https://github.com/OpenVPN/openvpn-gui/issues/729))
+
+ Note: Windows MSI was updated to I002 on June 19th. Changes in I002:
+ * Includes fix for [CVE-2025-50054](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50054)
+
+ | | | |
+ |-|-|-|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.14-I002-amd64.msi.asc)|[OpenVPN-2.6.14-I002-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.14-I002-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.14-I002-arm64.msi.asc)|[OpenVPN-2.6.14-I002-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.14-I002-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.14-I002-x86.msi.asc)|[OpenVPN-2.6.14-I002-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.14-I002-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.14.tar.gz.asc)|[openvpn-2.6.14.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.14.tar.gz)|
+
+ For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
+
+ ## OpenVPN 2.7_alpha2 -- Released 19 June 2025
+ The OpenVPN community project team is proud to release OpenVPN 2.7_alpha2. This is the first Alpha release for the feature release 2.7.0. As the Alpha name implies this is an early release build, this is not intended for production use.
+
+ Highlights of this release include:
+ * Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
+ * Improved Client support for DNS options
+ * Client implementations for Linux/BSD, included with the default install
+ * New client implementation for Windows, adding support for features like split DNS and DNSSEC
+ * Architectural improvements on Windows
+ * The `block-local` flag is now enforced with WFP filters
+ * Windows network adapters are now generated on demand
+ * Windows automatic service now runs as an unpriviledged user
+ * Support for server mode in win-dco driver
+ * Note: Support for the wintun driver has been removed. win-dco is now the default, tap-windows6 is the fallback solution for use-cases not covered by win-dco.
+ * Improved data channel
+ * Enforcement of AES-GCM usage limit
+ * Epoch data keys and packet format
+ * Support for new upstream DCO Linux kernel module
+ * This release supports the new `ovpn` DCO Linux kernel module which will be available in future upstream Linux kernel releases. Backports of the new module to current kernels are available via the [ovpn-backports project](https://github.com/OpenVPN/ovpn-backports).
+ * TLS 1.3 support with bleeding-edge mbedTLS versions
+
+ For details see [v2.7_alpha2/Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_alpha2/Changes.rst) and [v2.7_alpha1/Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_alpha1/Changes.rst)
+
+ Windows MSI changes since 2.6.14:
+ * Includes fix for [CVE-2025-50054](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50054)
+ * Built against OpenSSL 3.5.0
+ * Included openvpn-gui updated to 11.54.0.0
+ * Support for webauth in PLAP (Pre-Logon Access Provider) via QR code (github [openvpn-gui#687](https://github.com/OpenVPN/openvpn-gui/issues/687))
+ * Improve French (fr) and Turkish (tr) localization for OpenVPN GUI
+
+ | | | |
+ |-|-|-|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_alpha2-I001-amd64.msi.asc)|[OpenVPN-2.7_alpha2-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_alpha2-I001-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_alpha2-I001-arm64.msi.asc)|[OpenVPN-2.7_alpha2-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_alpha2-I001-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_alpha2-I001-x86.msi.asc)|[OpenVPN-2.7_alpha2-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_alpha2-I001-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7_alpha2.tar.gz.asc)|[openvpn-2.7_alpha2.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7_alpha2.tar.gz)|
+
+ For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9