Commit dab7ff

2026-04-22 14:57:20 uddr: v2.7.2 && v2.6.20 release
ReleaseHistory.md ..
@@ 1,3 1,88 @@
+ ## OpenVPN 2.7.2 -- Released 22 April 2026
+ The OpenVPN community project team is proud to release OpenVPN 2.7.2. This is a bugfix release containing security fixes.
+
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7.2/Changes.rst)
+
+ Security fixes:
+
+ * [CVE-2026-40215](https://www.cve.org/CVERecord?id=CVE-2026-40215): fix race condition in TLS handshake that could lead to leaking of
+ packet data from a previous handshake under specific circumstances
+ * [CVE-2026-35058](https://www.cve.org/CVERecord?id=CVE-2026-35058): fix server ASSERT() on receiving a suitably malformed packet with
+ a valid tls-crypt-v2 key
+
+ New features:
+
+ * management interface: permit input of very long passwords in
+ base64-encoded multiline format. Signal support to management
+ clients via "management version 6".
+
+ User-visible Changes:
+
+ * improve error messages on ``--verify-x509-name`` failures
+ * improve error logging when overlong username or passwords can not
+ be written to TLS buffer
+
+ Bugfixes:
+
+ * when using a config file with inlined username and no password,
+ fix prompting for the password from management interface.
+ * Windows: fix DNSSEC flag handling - this got never applied due to
+ a bad comparison being always false.
+ * Windows: fix deinstallation progress bar on adapter deletion.
+
+ Windows MSI changes since 2.7.1:
+ * Built against OpenSSL 3.6.2
+ * Included openvpn-gui updated to 11.63.0.0
+ * Translation cleanup. Remove obsolete strings related to support for OpenVPN < 2.0
+ * Translation updates.
+
+ | | | |
+ |-|-|-|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.2-I001-amd64.msi.asc)|[OpenVPN-2.7.2-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.2-I001-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.2-I001-arm64.msi.asc)|[OpenVPN-2.7.2-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.2-I001-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.2-I001-x86.msi.asc)|[OpenVPN-2.7.2-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.2-I001-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7.2.tar.gz.asc)|[openvpn-2.7.2.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7.2.tar.gz)|
+
+ For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
+
+ ## OpenVPN 2.6.20 -- Released 22 April 2026
+ The OpenVPN community project team is proud to release OpenVPN 2.6.20. This is a bugfix release containing security fixes.
+
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.20/Changes.rst)
+
+ Security fixes:
+
+ * [CVE-2026-40215](https://www.cve.org/CVERecord?id=CVE-2026-40215): fix race condition in TLS handshake that could lead to leaking of
+ packet data from a previous handshake under specific circumstances
+ * [CVE-2026-35058](https://www.cve.org/CVERecord?id=CVE-2026-35058): fix server ASSERT() on receiving a suitably malformed packet with
+ a valid tls-crypt-v2 key
+
+ Bugfixes:
+
+ * management: stop periodic bytecount output on mgmt client disconnection
+ * FreeBSD: make DCO work on systems with no IPv4 support
+ * FreeBSD: fix compilation with --enable-async-push on FreeBSD 15
+ * Linux: make DCO work on big endian architectures (MIPS, PowerPC)
+ * Windows: fix deinstallation progress bar on adapter deletion.
+ * Linux: fix problem with DCO kernel notifications getting lost, leading
+ to overcounting of number of connected clients and general confusion
+ between kernel and userland regarding peer status (Github [#900](https://github.com/OpenVPN/openvpn/issues/900), [#918](https://github.com/OpenVPN/openvpn/issues/918),
+ [#931](https://github.com/OpenVPN/openvpn/issues/931), [#919](https://github.com/OpenVPN/openvpn/issues/919), [#945](https://github.com/OpenVPN/openvpn/issues/945)) - this is a backport of the fixes in 2.7 plus the
+ infrastructural changes around DCO needed to support it.
+
+ Windows MSI changes since 2.6.19-I001:
+ * Built against OpenSSL 3.6.2
+ * Included openvpn-gui updated to 11.63.0.0
+ * Translation cleanup. Remove obsolete strings related to support for OpenVPN < 2.0
+ * Translation updates.
+
+ | | | |
+ |-|-|-|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.20-I001-amd64.msi.asc)|[OpenVPN-2.6.20-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.20-I001-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.20-I001-arm64.msi.asc)|[OpenVPN-2.6.20-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.20-I001-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.20-I001-x86.msi.asc)|[OpenVPN-2.6.20-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.20-I001-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.20.tar.gz.asc)|[openvpn-2.6.20.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.20.tar.gz)|
+
## OpenVPN 2.7.1 -- Released 31 March 2026
The OpenVPN community project team is proud to release OpenVPN 2.7.1. This is a bug fix release.
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9