Commit 5cd413

2026-10-07 12:17:37 flichtenheld: 2.7.8
Downloads.md ..
@@ 1,128 1,96 @@
- ## OpenVPN 2.7.7 -- Released 3 September 2026
- The OpenVPN community project team is proud to release OpenVPN 2.7.7. This is a bugfix release fixing
- many security issues.
+ ## OpenVPN 2.7.8 -- Released 7 October 2026
+ The OpenVPN community project team is proud to release OpenVPN 2.7.8. This is a bugfix release fixing
+ several security issues.
- For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7.7/Changes.rst)
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7.8/Changes.rst)
Security fixes:
- - reliability layer: avoid unbounded reliable TLS timeout, and ignore acks
- for packets that cannot be outstanding ([CVE-2026-84732](https://www.cve.org/CVERecord?id=CVE-2026-84732))
-
- Both reliability layer bugs found by Mark Bregman (Fox-IT), tracked in
- Github: OpenVPN/openvpn-private-issues#161
-
- - windows: fix `CreateProcess()` command line quoting for characters that
- are special to `cmd.exe`, where a combination of validation script plus
- rogue CA could lead to misbehavior ([CVE-2026-84256](https://www.cve.org/CVERecord?id=CVE-2026-84256))
-
- Bug found by Clouditera Security, tracked in Github:
- OpenVPN/openvpn-private-issues#159
-
- - windows: fix `tapctl` to always call `netsh.exe` with full path
- (as we do elsewhere) ([CVE-2026-84226](https://www.cve.org/CVERecord?id=CVE-2026-84226))
-
- Bug found by BreachX Zero Day Labs (using Typhon AI Mil v2), tracked in
- Github: OpenVPN/openvpn-private-issues#164
-
- - windows: don't use NULL DACL with system objects, namely the `--service`
- exit event and the `netsh.exe` guard semaphore. The old approach was
- prone to a local DoS where one user could interfere with other users'
- openvpn processes by blocking the netsh semaphore or sending events.
- This only affects setups not using the iservice, or using the automatic
- service to start/stop openvpn ([CVE-2026-82312](https://www.cve.org/CVERecord?id=CVE-2026-82312))
-
- Bug found by DEBRAJ BASAK, tracked in Github:
- OpenVPN/openvpn-private-issues#167
-
- - openvpnserv (windows): pass correct NRPT domains size - when IDN domains
- with UTF8 encoding were involved, a buffer overread could be achieved
- ([CVE-2026-78221](https://www.cve.org/CVERecord?id=CVE-2026-78221))
+ - Check for NULL-Bytes in certificate subjects - refuse all such certificates
+ now as "invalid" ([CVE-2026-84790](https://www.cve.org/CVERecord?id=CVE-2026-84790)).
- Bug found by BreachX Zero Day Labs (using Typhon AI Mil v2), in Github:
- OpenVPN/openvpn-private-issues#162
+ (Bug reported by Vivek Parikh, tracked in
+ Github: OpenVPN/openvpn-private-issues#163)
- - openvpnserv (windows): don't allow '/' in config paths. The APIs windows
- uses for path validation do not handle '/' as path separator, while the
- file open APIs do, so this could be used to circumvent our config path
- validation, leading to openvpn.exe starting a user-controlled config file
- even if administratively not allowed ([CVE-2026-78043](https://www.cve.org/CVERecord?id=CVE-2026-78043))
+ - TLS handshake with tls-crypt-v2: do not try to add a wrapped client key
+ if no key material is available (client bug in response to an ill-behaving
+ server).
- Bug found by BreachX Zero Day Labs (using Typhon AI Mil v2), in Github:
- OpenVPN/openvpn-private-issues#162
+ (No CVE assigned as "a malicious server can stop the client from working
+ properly" is not considered a CVE-worthy security issue according to the
+ CRA guidelines)
- - dhcp (windows): fix off-by-one in `write_dhcp_search_str()` temp buffer
- guard - suitable DHCP options could lead to a single-byte overflow of a
- temp buffer ([CVE-2026-81738](https://www.cve.org/CVERecord?id=CVE-2026-81738))
+ - options: fix unsigned underflow when clearing domain_search_list
+ ([CVE-2026-88964](https://www.cve.org/CVERecord?id=CVE-2026-84964))
- Bug found by Andre Kropp (Nexory) and ChinhNguyen, tracked in Github:
- OpenVPN/openvpn-private-issues#165
+ (Bug reported and fix contributed by Cole Munz,
+ tracked in Github: OpenVPN/openvpn-private-issues#178)
- - linux netlink: validate netlink replies against the request
+ - win32: stop cmd.exe from expanding variables in quoted arguments
+ ([CVE-2026-84256](https://www.cve.org/CVERecord?id=CVE-2026-84256))
- Suggested by Joshua Rogers as a security improvement, tracked in Github:
- OpenVPN/openvpn-private-issues#9
-
- - openvpnserv (windows): fix off-by-one on input validation
- (discovered while fixing CVE-2026-78221)
-
- - openvpnserv (windows): harden `CheckConfigPath()` a bit more
- (another improvement while working on CVE-2026-78043)
+ (Bug reported by Darren Carreras, tracked in Github:
+ OpenVPN/openvpn-private-issues#176)
User-visible Changes:
- - when using EPOCH data channel format, reduce the number of future keys
- from 16 to 4 - the previous calculation was wrong, and 4 spare keys are
- sufficient for 100+ Gbit/s links. This means less log spam in userland
- and fewer resources used in in-kernel implementations.
-
- Bugfixes:
-
- - work around a pubkey-handling bug in mbedTLS 4.1.0 and 4.2.0
- (supposedly fixed in 4.3.0)
-
- - multi: don't let stale-routes-check delete permanent routes -
- `--stale-routes-check` did not only delete dynamic cached routes, but
- also routes installed by `--iroute` and `--ifconfig-push`. Fixed by
- introducing route flags and restraining the check on them
- (Github: [OpenVPN/openvpn#1063](https://github.com/OpenVPN/openvpn/issues/1063))
+ - Certificate validation is now stricter regarding NULL bytes in strings
+ (see above). This might break existing installations if such certificates
+ exist and OpenSSL builds are used. mbedTLS builds always rejected this.
- - ssl: do not queue control ciphertext while a packet is still queued
- (fixes problems in TCP p2p handshake when both sides try to handshake
- at the same time)
- (Github: [OpenVPN/openvpn#1089](https://github.com/OpenVPN/openvpn/issues/1089))
+ - On a certificate with duplicate fields (multiple CN, for example) OpenSSL
+ builds would use the last one, mbedTLS builds use the first one - changed
+ in the mbedTLS build so behaviour is identical.
- - reenable xmit_hold when using p2p tcp-server and tls-server - in TCP
- server mode the server is not expected to initiate the TLS handshake.
- This was introduced by the multisocket code checking the wrong variable
- for socket protocol
- (Github: [OpenVPN/openvpn#1089](https://github.com/OpenVPN/openvpn/issues/1089))
-
- - clinat: do not adjust UDP checksum if zero (as per RFC768)
- (Github: [OpenVPN/openvpn#1037](https://github.com/OpenVPN/openvpn/issues/1037))
-
- - openssl: avoid resetting the HMAC key on every packet
- (Github: [OpenVPN/openvpn#1088](https://github.com/OpenVPN/openvpn/issues/1088))
-
- - openvpnserv (windows): fix log lines format string - interface names with
- international characters printed in some error messages need to be
- converted from UTF8 to UCS16 first.
-
- - fix format string specifier for size_t (%zu)
+ Bugfixes:
- - fix test_misc compile issues with -Werror
+ - DCO: remove installed iroutes at client exit time, not at delayed
+ multi instance cleanup time - otherwise there is a race with reconnecting
+ clients, possibly ending up having "no iroutes installed in the system
+ at all". Bug reported by OpenVPN Inc Access Server team.
+
+ - DCO Linux: fix remaining races between synchronous netlink operations
+ and incoming asynchronous notifications, by adding a second netlink socket
+ and strictly separating sync/async operations.
+
+ - Client: refuse incoming pushed option combination of epoch data format
+ with non-AEAD ciphers (restart session instead of aborting with a fatal
+ error).
+
+ - DCO (Linux and Windows): on failures to set up a new peer or install
+ key materials for a peer, do not exit OpenVPN with a fatal error. Instead,
+ signal the error up the call-chain and restart the (multi) instance.
+
+ The handshake is inherently racy when a peer is removed kernel-side
+ due to transport errors or timeouts, and userland does not yet know this
+ and wants to, for example, install new keys. This is fatal for the
+ particular client instance, but must not end the whole server process.
+
+ - DCO: stop fetching peer stats during client disconnect
+ The intention of the original code was to ensure reported counters
+ are always correct, but it did not work (because at query time, the peer
+ in kernel is already gone, so we only got an error message) - and very
+ inefficiently so (because we queried all the peers all the time).
+ End-of-session final counter values will be implemented properly by a
+ followup patch leveraging counters piggybacked on the kernel's
+ "DEL_PEER" notification message.
+
+ - p2mp server: improve handling of mbuf lists in the face of broadcast
+ or multicast traffic, and fix a bug on client exit that could lead
+ to a server queue deadlock in very particular scenarios.
Windows MSI changes since 2.7.6-I001:
- * Update included dco-win driver to v2.8.7
- * peer: fix use-after-free in multipeer peer table handling (Github: [OpenVPN/ovpn-dco-win#140](https://github.com/OpenVPN/ovpn-dco-win/pull/140))([CVE-2026-82325](https://www.cve.org/CVERecord?id=CVE-2026-82325))
- * inf: set the device security descriptor in the hardware key (Github: [OpenVPN/ovpn-dco-win#139](https://github.com/OpenVPN/ovpn-dco-win/pull/139))
+ * Update included dco-win driver to v2.8.13
+ * [CVE-2026-105390](https://www.cve.org/CVERecord?id=CVE-2026-105390) — a locking flaw allowed a local user with access to the driver's device to cause a system deadlock and denial of service, hanging the host until it was power-cycled.
+ * Performance improvements by moving to multi-core data processing. See [Release Notes](https://github.com/OpenVPN/ovpn-dco-win/releases/tag/2.8.13) for details.
+ * Update included OpenSSL to 3.6.5
| | | |
|-|-|-|
- |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-amd64.msi.asc)|[OpenVPN-2.7.7-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-amd64.msi)|
- |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-arm64.msi.asc)|[OpenVPN-2.7.7-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-arm64.msi)|
- |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-x86.msi.asc)|[OpenVPN-2.7.7-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-x86.msi)|
- |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7.7.tar.gz.asc)|[openvpn-2.7.7.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7.7.tar.gz)|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.8-I001-amd64.msi.asc)|[OpenVPN-2.7.8-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.8-I001-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.8-I001-arm64.msi.asc)|[OpenVPN-2.7.8-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.8-I001-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.8-I001-x86.msi.asc)|[OpenVPN-2.7.8-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.8-I001-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7.8.tar.gz.asc)|[openvpn-2.7.8.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7.8.tar.gz)|
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9