Commit a92ca4

2026-04-22 15:02:45 uddr: v2.7.2 && v2.6.20 releases
Downloads.md ..
@@ 1,109 1,87 @@
- ## OpenVPN 2.7.1 -- Released 31 March 2026
- The OpenVPN community project team is proud to release OpenVPN 2.7.1. This is a bug fix release.
+ ## OpenVPN 2.7.2 -- Released 22 April 2026
+ The OpenVPN community project team is proud to release OpenVPN 2.7.2. This is a bugfix release containing security fixes.
- For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7.1/Changes.rst)
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7.2/Changes.rst)
+
+ Security fixes:
+
+ * [CVE-2026-40215](https://www.cve.org/CVERecord?id=CVE-2026-40215): fix race condition in TLS handshake that could lead to leaking of
+ packet data from a previous handshake under specific circumstances
+ * [CVE-2026-35058](https://www.cve.org/CVERecord?id=CVE-2026-35058): fix server ASSERT() on receiving a suitably malformed packet with
+ a valid tls-crypt-v2 key
New features:
- - Add a new `username-only` flag argument to `--auth-user-pass` which
- will now make OpenVPN only query for username and send a dummy password
- to the server. This is only useful if auth schemes are used on the
- server side that will do some sort of external challenge base on username,
- and not password authentication. See discussion in
- GH [OpenVPN/openvpn#501](https://github.com/OpenVPN/openvpn/issues/501)
- (starting Jan 30, 2024).
- - Increase default sizing of internal hash maps to `4 * --max-clients`.
- The default used to be `256` with a `--max-clients` default of
- 1024 - this is bad for performance, while the memory savings are
- minimal. On a very memory constrained system, reduce `--max-clients`.
-
+ * management interface: permit input of very long passwords in
+ base64-encoded multiline format. Signal support to management
+ clients via "management version 6".
+
User-visible Changes:
- - When compiled with the AWS-LC SSL library, using `--tls-cert-profile`
- will now print a run-time warning - the library does not support it,
- so it would silently do nothing.
- - Systemd unit files: change LimitNPROC to TasksMax and increase limit
- (GH: [OpenVPN/openvpn#929](https://github.com/OpenVPN/openvpn/issues/929))
- - Documentation improvements.
- - port-share: log incoming connections at `verb 3`, not on `error`
- level anymore (GH: [OpenVPN/openvpn#976](https://github.com/OpenVPN/openvpn/issues/976)).
+ * improve error messages on ``--verify-x509-name`` failures
+ * improve error logging when overlong username or passwords can not
+ be written to TLS buffer
Bugfixes:
- - Fix usage of `--lport` inside a `<connection>` block - this got
- broken with the multi-socket patchset (GH: [OpenVPN/openvpn#995](https://github.com/OpenVPN/openvpn/issues/995))
- - Do not try to run auto-pam unit test when cross-compiling.
- - Do not break private-key passphrases of length >= 64
- (GH: [OpenVPN/openvpn#993](https://github.com/OpenVPN/openvpn/issues/993))
- - Fix obscure ASSERT() crash on TCP connects with TAP and no ip config.
- - Make DCO work on FreeBSD systems that have no IPv4 support in kernel
- (FreeBSD PR 286263)
- - Make DCO work on Linux on big endian systems (namely, MIPS and PowerPC)
- (GH: [OpenVPN/ovpn-dco#96](https://github.com/OpenVPN/ovpn-dco/issues/96))
- - Fixup responses to management interface ``version`` command (for >= 4)
- - Make `--enable-async-push` work on FreeBSD 15 (which has native
- inotify support, and consequently no libinotify.pc anymore)
- - Adjust some code parts to new "const" handling on string function
- returns (ISO C23, as implemented by glibc 2.43 and newer).
+ * when using a config file with inlined username and no password,
+ fix prompting for the password from management interface.
+ * Windows: fix DNSSEC flag handling - this got never applied due to
+ a bad comparison being always false.
+ * Windows: fix deinstallation progress bar on adapter deletion.
Windows MSI changes since 2.7.1:
- * Make sure that included openvpnserv2.exe is signed (GH: [OpenVPN/openvpn-build#1293](https://github.com/OpenVPN/openvpn-build/issues/1293))
- * Included openvpn-gui updated to 11.62.0.0
- * Translation updates
+ * Built against OpenSSL 3.6.2
+ * Included openvpn-gui updated to 11.63.0.0
+ * Translation cleanup. Remove obsolete strings related to support for OpenVPN < 2.0
+ * Translation updates.
| | | |
|-|-|-|
- |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.1-I001-amd64.msi.asc)|[OpenVPN-2.7.1-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.1-I001-amd64.msi)|
- |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.1-I001-arm64.msi.asc)|[OpenVPN-2.7.1-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.1-I001-arm64.msi)|
- |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.1-I001-x86.msi.asc)|[OpenVPN-2.7.1-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.1-I001-x86.msi)|
- |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7.1.tar.gz.asc)|[openvpn-2.7.1.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7.1.tar.gz)|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.2-I001-amd64.msi.asc)|[OpenVPN-2.7.2-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.2-I001-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.2-I001-arm64.msi.asc)|[OpenVPN-2.7.2-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.2-I001-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.2-I001-x86.msi.asc)|[OpenVPN-2.7.2-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.2-I001-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7.2.tar.gz.asc)|[openvpn-2.7.2.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7.2.tar.gz)|
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
- ## OpenVPN 2.6.19 -- Released 4 February 2026
- The OpenVPN community project team is proud to release OpenVPN 2.6.19. This is a bugfix release.
- 2.6.19 only fixes one small issue in the creation of the 2.6.18 release tarball. It was released
- on the same day as 2.6.18.
+ ## OpenVPN 2.6.20 -- Released 22 April 2026
+ The OpenVPN community project team is proud to release OpenVPN 2.6.20. This is a bugfix release containing security fixes.
- All the following mentioned changes are from 2.6.18.
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.20/Changes.rst)
- For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.19/Changes.rst)
+ Security fixes:
- User visible changes:
- * disable DCO if `--bind-dev` option is given (no support for this in
- the old out-of-kernel Linux DCO implementation)
- * on Windows, if using `--ip-win32 netsh` and not using the interactive
- service, IPv4 addresses would be installed as "permanent", possibly
- causing problems later on with using that IPv4 address on a different
- interface. Change to "store=active". (GH: [#915](https://github.com/OpenVPN/openvpn/issues/915))
- * improve pull-filter documentation, emphasizing possible problems if
- used as a naive security measure (reported by SRLabs)
+ * [CVE-2026-40215](https://www.cve.org/CVERecord?id=CVE-2026-40215): fix race condition in TLS handshake that could lead to leaking of
+ packet data from a previous handshake under specific circumstances
+ * [CVE-2026-35058](https://www.cve.org/CVERecord?id=CVE-2026-35058): fix server ASSERT() on receiving a suitably malformed packet with
+ a valid tls-crypt-v2 key
Bugfixes:
- * p2mp server: fix incorrect file descriptor handling on "inotify" FD
- during a SIGUSR1 restart (GH: [#966](https://github.com/OpenVPN/openvpn/issues/966))
- * management interface: fix bug where `--management-forget-disconnect`
- and `--management-signal` could be executed even if password authentication
- to managment interface was still pending (ZeroPath finding)
- * repair client-side interaction on reconnect between DCO event handling
- and `--persist-tun` - after a ping timeout and reconnect, the DCO
- event handler would not be armed, and the next ping timeout would not
- be received by userland, causing non-working connections with nothing
- in the openvpn log (Linux and FreeBSD only, GH: [#947](https://github.com/OpenVPN/openvpn/issues/947))
- * prevent crash on invalid server-ipv6 argument, calling `freeaddrinfo()`
- with a NULL pointer. This only affects OpenBSD. (Klemens Nanni).
-
- Windows MSI changes since 2.6.17-I001:
- * Built against OpenSSL 3.6.1
- * Included openvpn-gui updated to 11.61.0.0
- * translation updates
+
+ * management: stop periodic bytecount output on mgmt client disconnection
+ * FreeBSD: make DCO work on systems with no IPv4 support
+ * FreeBSD: fix compilation with --enable-async-push on FreeBSD 15
+ * Linux: make DCO work on big endian architectures (MIPS, PowerPC)
+ * Windows: fix deinstallation progress bar on adapter deletion.
+ * Linux: fix problem with DCO kernel notifications getting lost, leading
+ to overcounting of number of connected clients and general confusion
+ between kernel and userland regarding peer status (Github [#900](https://github.com/OpenVPN/openvpn/issues/900), [#918](https://github.com/OpenVPN/openvpn/issues/918),
+ [#931](https://github.com/OpenVPN/openvpn/issues/931), [#919](https://github.com/OpenVPN/openvpn/issues/919), [#945](https://github.com/OpenVPN/openvpn/issues/945)) - this is a backport of the fixes in 2.7 plus the
+ infrastructural changes around DCO needed to support it.
+
+ Windows MSI changes since 2.6.19-I001:
+ * Built against OpenSSL 3.6.2
+ * Included openvpn-gui updated to 11.63.0.0
+ * Translation cleanup. Remove obsolete strings related to support for OpenVPN < 2.0
+ * Translation updates.
| | | |
|-|-|-|
- |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.19-I001-amd64.msi.asc)|[OpenVPN-2.6.19-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.19-I001-amd64.msi)|
- |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.19-I001-arm64.msi.asc)|[OpenVPN-2.6.19-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.19-I001-arm64.msi)|
- |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.19-I001-x86.msi.asc)|[OpenVPN-2.6.19-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.19-I001-x86.msi)|
- |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.19.tar.gz.asc)|[openvpn-2.6.19.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.19.tar.gz)|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.20-I001-amd64.msi.asc)|[OpenVPN-2.6.20-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.20-I001-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.20-I001-arm64.msi.asc)|[OpenVPN-2.6.20-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.20-I001-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.20-I001-x86.msi.asc)|[OpenVPN-2.6.20-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.20-I001-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.20.tar.gz.asc)|[openvpn-2.6.20.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.20.tar.gz)|
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9