Commit ce5587

2025-09-22 14:14:01 flichtenheld: 2.6.15
Downloads.md ..
@@ 52,60 52,48 @@
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
- ## OpenVPN 2.6.14 -- Released 02 April 2025
- The OpenVPN community project team is proud to release OpenVPN 2.6.14. This is a bugfix release containing one security fix.
+ ## OpenVPN 2.6.15 -- Released 22 September 2025
+ The OpenVPN community project team is proud to release OpenVPN 2.6.15. This is a bugfix release.
- For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.14/Changes.rst)
-
- Security fixes:
-
- * [CVE-2025-2704](https://www.cve.org/CVERecord?id=CVE-2025-2704): fix possible `ASSERT()` on OpenVPN servers using `--tls-crypt-v2`
- Security scope: OpenVPN servers between 2.6.1 and 2.6.13 using
- `--tls-crypt-v2` can be made to abort with an `ASSERT()` message by
- sending a particular combination of authenticated and malformed packets.
- To trigger the bug, a valid tls-crypt-v2 client key is needed, or
- network observation of a handshake with a valid tls-crypt-v2 client key.
- No crypto integrity is violated, no data is leaked, and no remote
- code execution is possible.
- This bug does not affect OpenVPN clients.
- (Bug found by internal QA at OpenVPN Inc)
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.15/Changes.rst)
Bug fixes:
- * Linux DCO: repair source IP selection for `--multihome` (Qingfang Deng)
-
- Windows MSI changes since 2.6.13:
- * Built against OpenSSL 3.4.1
- * Included openvpn-gui updated to 11.52.0.0
- * Use correct `%TEMP%` directory for debug log file.
- * Disable config in menu listing if its ovpn file becomes inaccessible (github [openvpn-gui#729](https://github.com/OpenVPN/openvpn-gui/issues/729))
-
- Note: Windows MSI was updated to I002 on June 19th. Changes in I002:
- * Includes fix for [CVE-2025-50054](https://www.cve.org/CVERecord?id=CVE-2025-50054)
- * Built against OpenSSL 3.5.0
- * Included openvpn-gui updated to 11.54.0.0
- * Support for webauth in PLAP (Pre-Logon Access Provider) via QR code (github [openvpn-gui#687](https://github.com/OpenVPN/openvpn-gui/issues/687))
- * Improve French (fr) and Turkish (tr) localization for OpenVPN GUI
- * Included dco-win driver updated to 1.3.1
-
- Note: Windows MSI was updated to I003 on August 4th. Changes in I003:
- * Built against OpenSSL 3.5.1
- * Included openvpn-gui updated to 11.55.0.0
- * Fix Chinese localization for OpenVPN GUI
- * Included dco-win driver updated to 1.3.2
- * Fix several rare crashes reported via Windows crash reporting
- * Add float support
-
- Note: Windows MSI was updated to I004 on August 6th. Changes in I004:
- * Included dco-win driver updated to 1.3.3
- * Fix for recursive routing behavior
+ * on Windows, do not use "wmic.exe" any longer to set DNS search domain
+ (discontinued by Microsoft), use "powershell" fragment instead.
+ * on Windows, logging to the windows event log has been improved
+ (and logging of GetLastError() strings repaired). To make this work,
+ a new "openvpnmsgserv.dll" library is now installed and registered.
+ * DNS domain names are now strictly validated with a positive-list of
+ allowed characters (including UTF-8 high-bit-set bytes) before being
+ handed to powershell.
+ * Apply more checks to incoming TLS handshake packets before creating
+ new state - namely, verify message ID / acked ID for "valid range for
+ an initial packet". This fixes a problem with clients that float
+ very early but send control channel packet from the pre-float IP
+ (Github: [OpenVPN/openvpn#704](https://github.com/OpenVPN/openvpn/issues/704),
+ backported from 2.7_beta1.
+ * backport handling of client float notifications on FreeBSD 14/STABLE DCO
+ (see https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=289303)
+ * update GPL license text to latest version from FSF
+ * on Linux, on interfaces where applicable, OpenVPN explicitly configures
+ the broadcast address again. This was dropped for 2.6.0 "because
+ computers are smart and can do it themselves", but the kernel netlink
+ interface isn't, and will install "0.0.0.0". This does not normally
+ matter, but for broadcast-based applications that get the address to
+ use from "ifconfig", this change repairs functionality.
+
+ Windows MSI changes since 2.6.14-I003:
+ * Built against OpenSSL 3.5.3
+ * Included openvpn-gui updated to 11.56.0.0
+ * Fix "Cannot open the System Tray Menu with Keyboard" (Github: [OpenVPN/openvpn-gui#763](https://github.com/OpenVPN/openvpn-gui/issues/763))
| | | |
|-|-|-|
- |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.14-I004-amd64.msi.asc)|[OpenVPN-2.6.14-I004-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.14-I004-amd64.msi)|
- |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.14-I004-arm64.msi.asc)|[OpenVPN-2.6.14-I004-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.14-I004-arm64.msi)|
- |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.14-I004-x86.msi.asc)|[OpenVPN-2.6.14-I004-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.14-I004-x86.msi)|
- |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.14.tar.gz.asc)|[openvpn-2.6.14.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.14.tar.gz)|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.15-I001-amd64.msi.asc)|[OpenVPN-2.6.15-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.15-I001-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.15-I001-arm64.msi.asc)|[OpenVPN-2.6.15-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.15-I001-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.15-I001-x86.msi.asc)|[OpenVPN-2.6.15-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.15-I001-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.15.tar.gz.asc)|[openvpn-2.6.15.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.15.tar.gz)|
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9