Commit ded534

2026-09-23 14:19:48 uddr: 2.6.23
ReleaseHistory.md ..
@@ 1,3 1,68 @@
+ ## OpenVPN 2.6.23 -- Released 23 September 2026
+ The OpenVPN community project team is proud to release OpenVPN 2.6.23. This is a bugfix release fixing
+ several security issues.
+
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.23/Changes.rst)
+
+ Security fixes:
+
+ - ssl: do not trust the peer's request to resend the wrapped client key
+
+ Tracked in Github: OpenVPN/openvpn-private-issues#181
+
+ - reliability layer: avoid unbounded reliable TLS timeout, and ignore acks
+ for packets that cannot be outstanding ([CVE-2026-84732](https://www.cve.org/CVERecord?id=CVE-2026-84732))
+
+ Both reliability layer bugs found by Mark Bregman (Fox-IT), tracked in
+ Github: OpenVPN/openvpn-private-issues#161
+
+ - improve on `check_session_buf_not_used()`, catch possible double-free in
+ the lame duck case ([CVE-2026-84471](https://www.cve.org/CVERecord?id=CVE-2026-84471))
+
+ Bug reported by Andreas Gabriel Berbescu, tracked in Github:
+ OpenVPN/openvpn-private-issues#157, and by Haruki Oyama (Waseda
+ University), tracked in OpenVPN/openvpn-private-issues#132
+
+ - windows: fix `CreateProcess()` command line quoting for characters that
+ are special to `cmd.exe`, where a combination of validation script plus
+ rogue CA could lead to misbehavior ([CVE-2026-84256](https://www.cve.org/CVERecord?id=CVE-2026-84256))
+
+ Bug found by Clouditera Security, tracked in Github:
+ OpenVPN/openvpn-private-issues#159
+
+ - windows: fix `tapctl` to always call `netsh.exe` with full path
+ (as we do elsewhere) ([CVE-2026-84226](https://www.cve.org/CVERecord?id=CVE-2026-84226))
+
+ Bug found by BreachX Zero Day Labs (using Typhon AI Mil v2), tracked in
+ Github: OpenVPN/openvpn-private-issues#164
+
+ - windows: don't use NULL DACL with system objects, namely the `--service`
+ exit event and the `netsh.exe` guard semaphore. The old approach was
+ prone to a local DoS where one user could interfere with other users'
+ openvpn processes by blocking the netsh semaphore or sending events.
+ This only affects setups not using the iservice, or using the automatic
+ service to start/stop openvpn ([CVE-2026-82312](https://www.cve.org/CVERecord?id=CVE-2026-82312))
+
+ Bug found by DEBRAJ BASAK, tracked in Github:
+ OpenVPN/openvpn-private-issues#167
+
+ - dhcp (windows): fix off-by-one in `write_dhcp_search_str()` temp buffer
+ guard - suitable DHCP options could lead to a single-byte overflow of a
+ temp buffer ([CVE-2026-81738](https://www.cve.org/CVERecord?id=CVE-2026-81738))
+
+ Bug found by Andre Kropp (Nexory) and ChinhNguyen, tracked in Github:
+ OpenVPN/openvpn-private-issues#165
+
+ - openvpnserv (windows): detect and refuse sibling dirs in
+ `CheckConfigPath()` ([CVE-2026-81830](https://www.cve.org/CVERecord?id=CVE-2026-81830))
+
+ Bug found by Harshit Varu, tracked in Github:
+ OpenVPN/openvpn-private-issues#166
+
+ | | | |
+ |-|-|-|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.23.tar.gz.asc)|[openvpn-2.6.23.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.23.tar.gz)|
+
## OpenVPN 2.7.7 -- Released 3 September 2026
The OpenVPN community project team is proud to release OpenVPN 2.7.7. This is a bugfix release fixing
many security issues.
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9