For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
-
## OpenVPN 2.6.14 -- Released 02 April 2025
-
The OpenVPN community project team is proud to release OpenVPN 2.6.14. This is a bugfix release containing one security fix.
+
## OpenVPN 2.6.15 -- Released 22 September 2025
+
The OpenVPN community project team is proud to release OpenVPN 2.6.15. This is a bugfix release.
-
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.14/Changes.rst)
-
-
Security fixes:
-
-
* [CVE-2025-2704](https://www.cve.org/CVERecord?id=CVE-2025-2704): fix possible `ASSERT()` on OpenVPN servers using `--tls-crypt-v2`
-
Security scope: OpenVPN servers between 2.6.1 and 2.6.13 using
-
`--tls-crypt-v2` can be made to abort with an `ASSERT()` message by
-
sending a particular combination of authenticated and malformed packets.
-
To trigger the bug, a valid tls-crypt-v2 client key is needed, or
-
network observation of a handshake with a valid tls-crypt-v2 client key.
-
No crypto integrity is violated, no data is leaked, and no remote
-
code execution is possible.
-
This bug does not affect OpenVPN clients.
-
(Bug found by internal QA at OpenVPN Inc)
+
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.15/Changes.rst)
Bug fixes:
-
* Linux DCO: repair source IP selection for `--multihome` (Qingfang Deng)
-
-
Windows MSI changes since 2.6.13:
-
* Built against OpenSSL 3.4.1
-
* Included openvpn-gui updated to 11.52.0.0
-
* Use correct `%TEMP%` directory for debug log file.
-
* Disable config in menu listing if its ovpn file becomes inaccessible (github [openvpn-gui#729](https://github.com/OpenVPN/openvpn-gui/issues/729))
-
-
Note: Windows MSI was updated to I002 on June 19th. Changes in I002:
-
* Includes fix for [CVE-2025-50054](https://www.cve.org/CVERecord?id=CVE-2025-50054)
-
* Built against OpenSSL 3.5.0
-
* Included openvpn-gui updated to 11.54.0.0
-
* Support for webauth in PLAP (Pre-Logon Access Provider) via QR code (github [openvpn-gui#687](https://github.com/OpenVPN/openvpn-gui/issues/687))
-
* Improve French (fr) and Turkish (tr) localization for OpenVPN GUI
-
* Included dco-win driver updated to 1.3.1
-
-
Note: Windows MSI was updated to I003 on August 4th. Changes in I003:
-
* Built against OpenSSL 3.5.1
-
* Included openvpn-gui updated to 11.55.0.0
-
* Fix Chinese localization for OpenVPN GUI
-
* Included dco-win driver updated to 1.3.2
-
* Fix several rare crashes reported via Windows crash reporting
-
* Add float support
-
-
Note: Windows MSI was updated to I004 on August 6th. Changes in I004:
-
* Included dco-win driver updated to 1.3.3
-
* Fix for recursive routing behavior
+
* on Windows, do not use "wmic.exe" any longer to set DNS search domain
+
(discontinued by Microsoft), use "powershell" fragment instead.
+
* on Windows, logging to the windows event log has been improved
+
(and logging of GetLastError() strings repaired). To make this work,
+
a new "openvpnmsgserv.dll" library is now installed and registered.
+
* DNS domain names are now strictly validated with a positive-list of
+
allowed characters (including UTF-8 high-bit-set bytes) before being
+
handed to powershell.
+
* Apply more checks to incoming TLS handshake packets before creating
+
new state - namely, verify message ID / acked ID for "valid range for
+
an initial packet". This fixes a problem with clients that float
+
very early but send control channel packet from the pre-float IP