Commit ecf3c7

2025-11-17 14:47:15 uddr: OpenVPN-2.7_rc2-I009
Downloads.md ..
@@ 1,24 1,33 @@
- ## OpenVPN 2.7_rc1 -- Released 31 October 2025
- The OpenVPN community project team is proud to release OpenVPN 2.7_rc1. This is the first release candidate for the feature release 2.7.0.
-
- Feature changes since 2.7_beta3:
- * add warning for unsupported combination of --push and --tls-server
- * add warning for unsupported combination of `--reneg-bytes` or `--reneg-pkts` with DCO
- * remove perf_push()/perf_pop() infrastructure (because it did not work anymore, and compiler profiling will give better results today)
- * ensure compatibility with OpenSSL 3.6.0 - specifically, do not crash in t_lpback.sh trying to use new encrypt-then-mac (ETM) ciphers
- * improved PUSH_UPDATE server side support, which now handles changes of pushed ifconfig/ifconfig-ipv6 addresses correctly (send packets to new IP addresses to this client, stop sending packets to the old addresses).
- * freshen URLs all over the tree, and change to HTTPS where possible
- * on DCO Linux/FreeBSD, add support for clients receiving an IPv4/IPv6 address that is not part of the --server/--server-ipv6 subnet (= install extra on-interface host routes).
- * Windows programs use a new API for path name canonicalization now (PathCchCanonicalizeEx()) which will break building with MinGW on Ubuntu 22.04 -> Upgrade to 24.04 to make builds work again.
- * on Windows, when setting up WINS servers using netsh, use interface index instead of adapter name now ("as for all other netsh calls")
- * remove undocumented and unused --memstats feature
-
- Important bug fixes since 2.7_beta3:
- * even more type conversion related warnings have been fixed
- * more bugfixes related to BYTECOUNT display on the management interface and byte counters on DCO platforms in general
- * numerous minibugs reported by ZeroPath AI have been fixed (small memleaks, possible file descriptor leaks, improved sanity checks, add ASSERT() on function contracts, etc.)
+ ## OpenVPN 2.7_rc2 -- Released 17 November 2025
+ The OpenVPN community project team is proud to release OpenVPN 2.7_rc2. This is the second release candidate for the feature release 2.7.0.
+
+ Security fixes:
+ * [CVE-2025-12106](https://www.cve.org/CVERecord?id=CVE-2025-12106): IPv6 address parsing: fix buffer overread on invalid input
+ * [CVE-2025-13086](https://www.cve.org/CVERecord?id=CVE-2025-13086): HMAC verification check: fix incorrect memcmp() call
- For a list of all changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_beta3...v2.7_rc1).
+ Important bug fixes since 2.7_rc1:
+ * even more type conversion related warnings have been fixed
+ * DCO FreeBSD improvements:
+ * improving debug messages (verb 6)
+ * implement client-side counter handling
+ * repair --inactive (and document shortcomings)
+ * repair handling of DCO disconnection notifications in --client mode
+ * Windows/Service improvements, hardening, bugfixes
+ * fix DNS address list generation (if 3 or more --dns addresses in use)
+ * fix DNS server undo_list
+ * disallow "stdin" as config name unless user has OpenVPN admin privs
+ * fix compilation errors with MSVC v19
+ * iservice: improve validation of config path (pathcc lib)
+ * [NOTE: this breaks OpenVPN compatibility with Windows 7]
+ * tapctl: refactor, improve output, change driver default to ovpn-dco
+ * iservice: when restoring iface metrics, enforce correct ifindex
+ * improve cmocka unit test assert() handling
+ * PUSH_UPDATE server: fix reporting of client IPs in ``status`` output after pushing a new IPv4/IPv6 address to client
+ * AEAD cipher safety margins: fix calculation of AEAD blocks in use (old code would undercount blocks)
+ * fix invalid pointer creation / memory overread in tls_pre_decrypt
+ * deprecate ``--opt-verify`` (change into no-op + warning)
+
+ For a list of all changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_rc1...v2.7_rc2).
Highlights of 2.7 include:
* Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
@@ 46,27 55,27 @@
* "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
* COPYING: license details only relevant to our Windows installers have been updated and moved to the openvpn-build repo
- For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_rc1/Changes.rst)
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_rc2/Changes.rst)
- Windows MSI changes since 2.7_beta3:
+ Windows MSI changes since 2.7_rc1:
* Built against OpenSSL 3.6.0
- * Included openvpn-gui updated to 11.57.0.0
- * Encrypt username saved in registry
- * Avoid blocking calls during WM_OVPN_ECHOMSG processing
- * Fixes segfault when echo msg-notify happens with no message to display (Github: [OpenVPN/openvpn-gui#771](https://github.com/OpenVPN/openvpn-gui/issues/771))
- * Check the path of the process listening on management port
- * Error out if imported profile file name is too long
- * Disallow Windows special filenames for imported profile
- * Replace % characters in param->id as it's used in format template
- * Excplicitly check that urls start with http:// or https://
+ * Included openvpn-gui updated to 11.58.0.0
+ * Check the return value of GetProp()
+ * Make config path check similar to that in interactive service
+ * Escape the type id of password message received from openvpn
+ * Add a message source for event logging
+ * Check correct management daemon path when OpenVPN3 is enabled
+ * Fix OpenVPN3 radio button label size when OVPN3 is enabled
+ * Use GetTempPath() for debug file in plap as well
+ * Migrate all saved plain usernames to encrypted format
* Included win-dco driver updated to 2.8.0
| | | |
|-|-|-|
- |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc1-I008-amd64.msi.asc)|[OpenVPN-2.7_rc1-I008-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc1-I008-amd64.msi)|
- |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc1-I008-arm64.msi.asc)|[OpenVPN-2.7_rc1-I008-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc1-I008-arm64.msi)|
- |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc1-I008-x86.msi.asc)|[OpenVPN-2.7_rc1-I008-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc1-I008-x86.msi)|
- |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc1.tar.gz.asc)|[openvpn-2.7_rc1.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc1.tar.gz)|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc2-I009-amd64.msi.asc)|[OpenVPN-2.7_rc2-I009-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc2-I009-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc2-I009-arm64.msi.asc)|[OpenVPN-2.7_rc2-I009-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc2-I009-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc2-I009-x86.msi.asc)|[OpenVPN-2.7_rc2-I009-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc2-I009-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc2.tar.gz.asc)|[openvpn-2.7_rc2.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc2.tar.gz)|
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
@@ 130,4 139,4 @@
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.9-I601-x86.msi.asc)|[OpenVPN-2.5.9-I601-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.9-I601-x86.msi)|
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.5.9.tar.gz.asc)|[openvpn-2.5.9.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.5.9.tar.gz)|
- ## [Full Release History](https://community.openvpn.net/ReleaseHistory)
+ #### [Full Release History](https://community.openvpn.net/ReleaseHistory)
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9