Commit 619ad4

2026-01-15 18:05:51 uddr: 2.7-rc5-I013
Downloads.md ..
@@ 1,42 1,32 @@
- ## OpenVPN 2.7_rc4 -- Released 17 December 2025
- The OpenVPN community project team is proud to release OpenVPN 2.7_rc4. This is the fourth release candidate for the feature release 2.7.0.
-
- Important bug fixes since 2.7_rc3:
- * Windows interactive service: do not configure adapter DNS if
- there are no search-domains but there are resolve-domains (which
- get resolved via NRPT rules) - GH: [OpenVPN/openvpn#473](https://github.com/OpenVPN/openvpn/issues/473)
- * improve documentation and error messages for a number of deprecated
- options
- * improve documentation for not-really-deprecated-yet ``--ns-cert-type``
- * Windows IPv4 configuration with netsh.exe: ensure addresses are added
- with "store=active" (ensure proper cleanup) - GH: [OpenVPN/openvpn#915](https://github.com/OpenVPN/openvpn/issues/915)
- * Windows: set UTF8 code page in openvpn.exe manifest, to make cert/key
- loading work again for files with non-ASCII characters in their file
- name (GH: [OpenVPN/openvpn#920](https://github.com/OpenVPN/openvpn/issues/920))
- * tun.c: unify read_tun()/write_tun() functions for all BSD platforms
- * more type conversion related cleanups
- * add NULL check before freeaddrinfo() call, which might lead to a
- crash on OpenBSD (GH: [OpenVPN/openvpn#930](https://github.com/OpenVPN/openvpn/issues/930))
- * add NULL check to mbedtls handling of external and inline certificates
- * add check for auth none / cipher none on FreeBSD DCO
- * add CAP_SYS_NICE to positive list in Linux systemd unit files
- (GH: [OpenVPN/openvpn#834](https://github.com/OpenVPN/openvpn/issues/834))
- * drop mbedtls 2.x support (which is end of life, and work on mbedtls 4
- is much simplified by not having to take care of 2.x compat as well)
- * PUSH_UPDATE: bugfix for the client side where split/continued messages
- (due to large number of "route" statements) would not correctly handle
- the full set of routes. Add unit test. (GH: [OpenVPN/openvpn#925](https://github.com/OpenVPN/openvpn/issues/925))
- * new unit test module for mbuf handling
- * deprecate --fast-io option (it got partially broken by the multisocket
- implementation, and the benefits of the existing implementation did
- not outweigh the extra code complexity to make it work again)
- * change the ssl_ctx in struct tls_options to be a pointer - this is
- a shared data structure between various contexts, but previously it
- was shallow-copied, leading to needless CRL reloading - and when
- working on implementing the new OpenSSL CRL API, to segfaults
- (the existing code works, as these new APIs are not used yet).
-
- For a list of all changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_rc3...v2.7_rc4).
+ ## OpenVPN 2.7_rc5 -- Released 15 January 2026
+ The OpenVPN community project team is proud to release OpenVPN 2.7_rc5. This is the fifth release candidate for the feature release 2.7.0.
+
+ Security fixes:
+ * [CVE-2025-15497](https://www.cve.org/CVERecord?id=CVE-2025-15497): in epoch key handling (an authenticated remote system
+ can send a valid OpenVPN data packet that triggers an edge case
+ where a too-strict check would trigger an ASSERT(), exiting OpenVPN)
+
+ Important bug fixes since 2.7_rc4:
+ * remove "resolve --remote on incoming TCP connects on --tcp-server"
+ code base, because that did not work in a long time (since 2.4) and
+ is seen as too obscure and too complicated to rescue.
+ * repair interaction between DCO and persist-tun after reconnection
+ (in this case the client side would fail to set up the DCO event
+ handler, and not notice further --ping timeouts - GH: #947)
+ * remove ENABLE_X509ALTUSERNAME conditional, always enabling
+ "configure --enable-x509-alt-username". Effectively no change in
+ code size, and one less build variant to maintain and test (GH: [OpenVPN/openvpn#917](https://github.com/OpenVPN/openvpn/issues/917)).
+ * require "script-security 2" when using `--dev unix:<program>`
+ * socks client: fix and improve various code parts
+ * configure etc: drop support for systemd 216 and older, adapt
+ other checks to reflect modern systemd setups
+ * fix unit test building with libcmocka 2.0+
+ * fix Android build warnings about unused variables/methods
+ * allow --test-crypto to run without --secret
+ (prepare for removal of --secret after 2.7)
+ * improve WolfSSL build compatibility
+
+ For a list of all changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_rc4...v2.7_rc5).
Highlights of 2.7 include:
* Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
@@ 64,20 54,19 @@
* "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
* COPYING: license details only relevant to our Windows installers have been updated and moved to the openvpn-build repo
- For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_rc4/Changes.rst)
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_rc5/Changes.rst)
- Windows MSI changes since 2.7_rc3:
+ Windows MSI changes since 2.7_rc4:
* Built against OpenSSL 3.6.0
- * Included openvpn-gui updated to 11.60.0.0
- * Update copyright year in About dialog
+ * Included openvpn-gui updated to 11.61.0.0
* Included win-dco driver updated to 2.8.0
| | | |
|-|-|-|
- |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc4-I012-amd64.msi.asc)|[OpenVPN-2.7_rc4-I012-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc4-I012-amd64.msi)|
- |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc4-I012-arm64.msi.asc)|[OpenVPN-2.7_rc4-I012-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc4-I012-arm64.msi)|
- |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc4-I012-x86.msi.asc)|[OpenVPN-2.7_rc4-I012-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc4-I012-x86.msi)|
- |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc4.tar.gz.asc)|[openvpn-2.7_rc4.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc4.tar.gz)|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc5-I013-amd64.msi.asc)|[OpenVPN-2.7_rc5-I013-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc5-I013-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc5-I013-arm64.msi.asc)|[OpenVPN-2.7_rc5-I013-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc5-I013-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc5-I013-x86.msi.asc)|[OpenVPN-2.7_rc5-I013-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc5-I013-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc5.tar.gz.asc)|[openvpn-2.7_rc5.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc5.tar.gz)|
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9