Commit ef2447

2026-09-03 14:33:00 uddr: 2.7.7 release
Downloads.md ..
@@ 1,86 1,128 @@
- ## OpenVPN 2.7.6 -- Released 5 August 2026
- The OpenVPN community project team is proud to release OpenVPN 2.7.6. This is a bugfix release fixing
- several security issues.
+ ## OpenVPN 2.7.7 -- Released 3 September 2026
+ The OpenVPN community project team is proud to release OpenVPN 2.7.7. This is a bugfix release fixing
+ many security issues.
- For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7.6/Changes.rst)
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7.7/Changes.rst)
Security fixes:
- - openvpnserv (windows): better scrutinize command line passed in
- from the control socket to openvpn. This would lead to circumventing
- admin restrictions on allowed openvpn config directories (but never
- to "read files the user has no permissions for") ([CVE-2026-63649](https://www.cve.org/CVERecord?id=CVE-2026-63649))
+ - reliability layer: avoid unbounded reliable TLS timeout, and ignore acks
+ for packets that cannot be outstanding ([CVE-2026-84732](https://www.cve.org/CVERecord?id=CVE-2026-84732))
- Bug found by 章鱼哥 (www.aipyaipy.com)
+ Both reliability layer bugs found by Mark Bregman (Fox-IT), tracked in
+ Github: OpenVPN/openvpn-private-issues#161
- - dco: make key state desync recoverable
+ - windows: fix `CreateProcess()` command line quoting for characters that
+ are special to `cmd.exe`, where a combination of validation script plus
+ rogue CA could lead to misbehavior ([CVE-2026-84256](https://www.cve.org/CVERecord?id=CVE-2026-84256))
- This was reported as a "with suitable timing, a key-update de-sync between
- OpenVPN and the kernel could trigger an ASSERT()", and was initially
- handled as security report. It turned out to be not exploitable, but the
- state machine was not very robust and so the opportunity was used to
- improve the code.
+ Bug found by Clouditera Security, tracked in Github:
+ OpenVPN/openvpn-private-issues#159
- Bug found by 章鱼哥 (www.aipyaipy.com)
+ - windows: fix `tapctl` to always call `netsh.exe` with full path
+ (as we do elsewhere) ([CVE-2026-84226](https://www.cve.org/CVERecord?id=CVE-2026-84226))
- - make ``--x509-username-field`` work with mbedTLS.
+ Bug found by BreachX Zero Day Labs (using Typhon AI Mil v2), tracked in
+ Github: OpenVPN/openvpn-private-issues#164
- In very particular setups, together with a CA creating matching certificates,
- this could lead to unintentionally permitting a certificate that should
- not have. This is why this was considered a (low-prio) security bug and a
- CVE ID was assigned ([CVE-2026-63650](https://www.cve.org/CVERecord?id=CVE-2026-63650))
+ - windows: don't use NULL DACL with system objects, namely the `--service`
+ exit event and the `netsh.exe` guard semaphore. The old approach was
+ prone to a local DoS where one user could interfere with other users'
+ openvpn processes by blocking the netsh semaphore or sending events.
+ This only affects setups not using the iservice, or using the automatic
+ service to start/stop openvpn ([CVE-2026-82312](https://www.cve.org/CVERecord?id=CVE-2026-82312))
- Bug found by 章鱼哥 (www.aipyaipy.com)
+ Bug found by DEBRAJ BASAK, tracked in Github:
+ OpenVPN/openvpn-private-issues#167
- User-visible Changes:
+ - openvpnserv (windows): pass correct NRPT domains size - when IDN domains
+ with UTF8 encoding were involved, a buffer overread could be achieved
+ ([CVE-2026-78221](https://www.cve.org/CVERecord?id=CVE-2026-78221))
+
+ Bug found by BreachX Zero Day Labs (using Typhon AI Mil v2), in Github:
+ OpenVPN/openvpn-private-issues#162
+
+ - openvpnserv (windows): don't allow '/' in config paths. The APIs windows
+ uses for path validation do not handle '/' as path separator, while the
+ file open APIs do, so this could be used to circumvent our config path
+ validation, leading to openvpn.exe starting a user-controlled config file
+ even if administratively not allowed ([CVE-2026-78043](https://www.cve.org/CVERecord?id=CVE-2026-78043))
+
+ Bug found by BreachX Zero Day Labs (using Typhon AI Mil v2), in Github:
+ OpenVPN/openvpn-private-issues#162
+
+ - dhcp (windows): fix off-by-one in `write_dhcp_search_str()` temp buffer
+ guard - suitable DHCP options could lead to a single-byte overflow of a
+ temp buffer ([CVE-2026-81738](https://www.cve.org/CVERecord?id=CVE-2026-81738))
- - if `--dev` is not specified, default to `--dev tun` - so for the
- tun case, this option can now be left out of the openvpn config.
+ Bug found by Andre Kropp (Nexory) and ChinhNguyen, tracked in Github:
+ OpenVPN/openvpn-private-issues#165
- - `--ping` and `--keepalive` settings are now limited to 24 hours
- maximum - the primary reason for that is to avoid lots of extra code
- in the DCO kernel to handle arbitrarily large values without overflowing
- 32 bit integers. 24h is considered much higher than any reasonable use.
+ - linux netlink: validate netlink replies against the request
- - The `TCP_NODELAY` socket flag is now "always on". The `--tcp-nodelay`
- option is kept, because setting it on a p2mp server also enables pushing
- of `socket-flags TCP_NODELAY` to clients, which might not have this
- code change yet.
+ Suggested by Joshua Rogers as a security improvement, tracked in Github:
+ OpenVPN/openvpn-private-issues#9
- - Remove `--providers` from `--help` output on mbedTLS builds.
+ - openvpnserv (windows): fix off-by-one on input validation
+ (discovered while fixing CVE-2026-78221)
+
+ - openvpnserv (windows): harden `CheckConfigPath()` a bit more
+ (another improvement while working on CVE-2026-78043)
+
+ User-visible Changes:
+
+ - when using EPOCH data channel format, reduce the number of future keys
+ from 16 to 4 - the previous calculation was wrong, and 4 spare keys are
+ sufficient for 100+ Gbit/s links. This means less log spam in userland
+ and fewer resources used in in-kernel implementations.
Bugfixes:
- - refuse incoming HARD RESET packets with a sequence ID != 0
- (this is basically making an OpenVPN server ignore and log a
- "should never happen" client-side misbehaviour, which could lead to
- TLS handshake establishment failures in p2p TLS setups)
+ - work around a pubkey-handling bug in mbedTLS 4.1.0 and 4.2.0
+ (supposedly fixed in 4.3.0)
- - correctly calculate packet id size if epoch packet format is in use -
- this was off by 4, for connections openvpn 2.7+ to openvpn 2.7+,
- exceeding "mssfix mtu" headroom by those 4 bytes
- (Github: [OpenVPN/openvpn#1074](https://github.com/OpenVPN/openvpn/issues/1074))
+ - multi: don't let stale-routes-check delete permanent routes -
+ `--stale-routes-check` did not only delete dynamic cached routes, but
+ also routes installed by `--iroute` and `--ifconfig-push`. Fixed by
+ introducing route flags and restraining the check on them
+ (Github: [OpenVPN/openvpn#1063](https://github.com/OpenVPN/openvpn/issues/1063))
- - correct minimum packet length check for 802.1q tagged packets
- (Github: [OpenVPN/openvpn#1044](https://github.com/OpenVPN/openvpn/issues/1044)).
+ - ssl: do not queue control ciphertext while a packet is still queued
+ (fixes problems in TCP p2p handshake when both sides try to handshake
+ at the same time)
+ (Github: [OpenVPN/openvpn#1089](https://github.com/OpenVPN/openvpn/issues/1089))
- This was also reported (twice) as a security bug, as technically
- OpenVPN with `--client-nat` would read and write up to 4 bytes
- "after the end of the packet" - but due to the OpenVPN packet buffer
- layouts, which are always full-frame-sized this is fully safe and has
- no adverse consequences.
+ - reenable xmit_hold when using p2p tcp-server and tls-server - in TCP
+ server mode the server is not expected to initiate the TLS handshake.
+ This was introduced by the multisocket code checking the wrong variable
+ for socket protocol
+ (Github: [OpenVPN/openvpn#1089](https://github.com/OpenVPN/openvpn/issues/1089))
+
+ - clinat: do not adjust UDP checksum if zero (as per RFC768)
+ (Github: [OpenVPN/openvpn#1037](https://github.com/OpenVPN/openvpn/issues/1037))
+
+ - openssl: avoid resetting the HMAC key on every packet
+ (Github: [OpenVPN/openvpn#1088](https://github.com/OpenVPN/openvpn/issues/1088))
+
+ - openvpnserv (windows): fix log lines format string - interface names with
+ international characters printed in some error messages need to be
+ converted from UTF8 to UCS16 first.
+
+ - fix format string specifier for size_t (%zu)
+ - fix test_misc compile issues with -Werror
- Windows MSI changes since 2.7.5-I001:
- * Update included dco-win driver to v2.8.4
- * fix control channel stall (Github: [ovpn-dco-win/issues/137](https://github.com/OpenVPN/ovpn-dco-win/issues/137))
+ Windows MSI changes since 2.7.6-I001:
+ * Update included dco-win driver to v2.8.7
+ * peer: fix use-after-free in multipeer peer table handling (Github: https://github.com/OpenVPN/ovpn-dco-win/pull/140)
+ * inf: set the device security descriptor in the hardware key (Github: https://github.com/OpenVPN/ovpn-dco-win/pull/139)
| | | |
|-|-|-|
- |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.6-I001-amd64.msi.asc)|[OpenVPN-2.7.6-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.6-I001-amd64.msi)|
- |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.6-I001-arm64.msi.asc)|[OpenVPN-2.7.6-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.6-I001-arm64.msi)|
- |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.6-I001-x86.msi.asc)|[OpenVPN-2.7.6-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.6-I001-x86.msi)|
- |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7.6.tar.gz.asc)|[openvpn-2.7.6.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7.6.tar.gz)|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-amd64.msi.asc)|[OpenVPN-2.7.7-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-arm64.msi.asc)|[OpenVPN-2.7.7-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-x86.msi.asc)|[OpenVPN-2.7.7-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7.7.tar.gz.asc)|[openvpn-2.7.7.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7.7.tar.gz)|
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9