The OpenVPN community project team is proud to release OpenVPN 2.7_rc3. This is the third release candidate for the feature release 2.7.0.
-
-
Security fixes:
-
* [CVE-2025-13751](https://www.cve.org/CVERecord?id=CVE-2025-13751): Windows/interactive service: fix bug where the interactive service would error-exit in
-
certain error conditions instead of just logging the fact and
-
continuing. After the error-exit, OpenVPN connections will no
-
longer work until the service is restarted (or the system rebooted).
-
This can be triggered by any authenticated local user, and has
-
thus been classified as a "local denial of service" attack.
-
-
Important bug fixes since 2.7_rc2:
-
* Windows/Interactive Service bugfixes:
-
many small bugfixes to registry-related DNS domain handling
-
* Windows/Interactive Service: harden service pipe handling
-
close a small race condition, and add restrictive ACLs
-
* more type conversion related warnings have been fixed
-
* --multihome behaviour regarding egress interface selection has been
-
changed. See Changes.rst and manpage for details.
-
* cleanup dead code in event handling code (leftover of the multisocket
-
patch set)
-
* add new feature, --tls-crypt-v2-max-age n. See Changes.rst and
-
manpage for details.
-
* improve documentation to point out the pitfalls of case-insensitive
-
filesystems and --client-config-dir
-
* split default gateway query logic in two:
-
* for --redirect-gateway functionality, query for the gateway towards
-
the actual IP address of the VPN server connecting to
-
* for the "net_gateway" special destination for --route, and the
-
corresponding environment variable, always query for 0.0.0.0 / ::
-
(this will only make a difference in certain scenarios using a local
-
proxy, or on a system with multiple interfaces, not using the "default
-
route" for the VPN connection * see github#890)
-
* upgrade embedded pkcs11-helper vcpkg + pkcs11-uri patch to 1.31
* drop mbedtls 2.x support (which is end of life, and work on mbedtls 4
+
is much simplified by not having to take care of 2.x compat as well)
+
* PUSH_UPDATE: bugfix for the client side where split/continued messages
+
(due to large number of "route" statements) would not correctly handle
+
the full set of routes. Add unit test. (GH: [OpenVPN/openvpn#925](https://github.com/OpenVPN/openvpn/issues/925))
+
* new unit test module for mbuf handling
+
* deprecate --fast-io option (it got partially broken by the multisocket
+
implementation, and the benefits of the existing implementation did
+
not outweigh the extra code complexity to make it work again)
+
* change the ssl_ctx in struct tls_options to be a pointer - this is
+
a shared data structure between various contexts, but previously it
+
was shallow-copied, leading to needless CRL reloading - and when
+
working on implementing the new OpenSSL CRL API, to segfaults
+
(the existing code works, as these new APIs are not used yet).
+
+
For a list of all changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_rc3...v2.7_rc4).
Highlights of 2.7 include:
* Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
@@ 65,21 64,20 @@
* "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
* COPYING: license details only relevant to our Windows installers have been updated and moved to the openvpn-build repo
-
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_rc3/Changes.rst)
+
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_rc4/Changes.rst)
-
Windows MSI changes since 2.7_rc2:
+
Windows MSI changes since 2.7_rc3:
* Built against OpenSSL 3.6.0
-
* Included openvpn-gui updated to 11.59.0.0
-
* Authorize config before opening the service pipe
-
* Remove dependence on pathcch.dll not in Windows 7
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.