Commit efd25f

2025-11-28 18:05:54 uddr: 2.6.17 and 2.7-rc3 release
Downloads.md ..
@@ 1,33 1,43 @@
- ## OpenVPN 2.7_rc2 -- Released 17 November 2025
- The OpenVPN community project team is proud to release OpenVPN 2.7_rc2. This is the second release candidate for the feature release 2.7.0.
+ ## OpenVPN 2.7_rc3 -- Released 28 November 2025
+ The OpenVPN community project team is proud to release OpenVPN 2.7_rc3. This is the third release candidate for the feature release 2.7.0.
Security fixes:
- * [CVE-2025-12106](https://www.cve.org/CVERecord?id=CVE-2025-12106): IPv6 address parsing: fix buffer overread on invalid input
- * [CVE-2025-13086](https://www.cve.org/CVERecord?id=CVE-2025-13086): HMAC verification check: fix incorrect memcmp() call
-
- Important bug fixes since 2.7_rc1:
- * even more type conversion related warnings have been fixed
- * DCO FreeBSD improvements:
- * improving debug messages (verb 6)
- * implement client-side counter handling
- * repair --inactive (and document shortcomings)
- * repair handling of DCO disconnection notifications in --client mode
- * Windows/Service improvements, hardening, bugfixes
- * fix DNS address list generation (if 3 or more --dns addresses in use)
- * fix DNS server undo_list
- * disallow "stdin" as config name unless user has OpenVPN admin privs
- * fix compilation errors with MSVC v19
- * iservice: improve validation of config path (pathcc lib)
- * [NOTE: this breaks OpenVPN compatibility with Windows 7]
- * tapctl: refactor, improve output, change driver default to ovpn-dco
- * iservice: when restoring iface metrics, enforce correct ifindex
- * improve cmocka unit test assert() handling
- * PUSH_UPDATE server: fix reporting of client IPs in ``status`` output after pushing a new IPv4/IPv6 address to client
- * AEAD cipher safety margins: fix calculation of AEAD blocks in use (old code would undercount blocks)
- * fix invalid pointer creation / memory overread in tls_pre_decrypt
- * deprecate ``--opt-verify`` (change into no-op + warning)
-
- For a list of all changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_rc1...v2.7_rc2).
+ * [CVE-2025-13751](https://www.cve.org/CVERecord?id=CVE-2025-13751): Windows/interactive service: fix bug where the interactive service would error-exit in
+ certain error conditions instead of just logging the fact and
+ continuing. After the error-exit, OpenVPN connections will no
+ longer work until the service is restarted (or the system rebooted).
+ This can be triggered by any authenticated local user, and has
+ thus been classified as a "local denial of service" attack.
+
+ Important bug fixes since 2.7_rc2:
+ * Windows/Interactive Service bugfixes:
+ many small bugfixes to registry-related DNS domain handling
+ * Windows/Interactive Service: harden service pipe handling
+ close a small race condition, and add restrictive ACLs
+ * more type conversion related warnings have been fixed
+ * --multihome behaviour regarding egress interface selection has been
+ changed. See Changes.rst and manpage for details.
+ * cleanup dead code in event handling code (leftover of the multisocket
+ patch set)
+ * add new feature, --tls-crypt-v2-max-age n. See Changes.rst and
+ manpage for details.
+ * improve documentation to point out the pitfalls of case-insensitive
+ filesystems and --client-config-dir
+ * split default gateway query logic in two:
+ * for --redirect-gateway functionality, query for the gateway towards
+ the actual IP address of the VPN server connecting to
+ * for the "net_gateway" special destination for --route, and the
+ corresponding environment variable, always query for 0.0.0.0 / ::
+ (this will only make a difference in certain scenarios using a local
+ proxy, or on a system with multiple interfaces, not using the "default
+ route" for the VPN connection * see github#890)
+ * upgrade embedded pkcs11-helper vcpkg + pkcs11-uri patch to 1.31
+ * CMake / autoconf cleanup wrt unused checks, outdated old-Linux checks,
+ Windows oddities
+ * DCO (primarily Linux): improve handling of bulk notifications from
+ kernel (do not lose notifications, do not crash) ([github#900](https://github.com/OpenVPN/openvpn/issues/900))
+
+ For a list of all changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_rc2...v2.7_rc3).
Highlights of 2.7 include:
* Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
@@ 55,80 65,54 @@
* "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
* COPYING: license details only relevant to our Windows installers have been updated and moved to the openvpn-build repo
- For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_rc2/Changes.rst)
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_rc3/Changes.rst)
- Windows MSI changes since 2.7_rc1:
+ Windows MSI changes since 2.7_rc2:
* Built against OpenSSL 3.6.0
- * Included openvpn-gui updated to 11.58.0.0
- * Check the return value of GetProp()
- * Make config path check similar to that in interactive service
- * Escape the type id of password message received from openvpn
- * Add a message source for event logging
- * Check correct management daemon path when OpenVPN3 is enabled
- * Fix OpenVPN3 radio button label size when OVPN3 is enabled
- * Use GetTempPath() for debug file in plap as well
- * Migrate all saved plain usernames to encrypted format
+ * Included openvpn-gui updated to 11.59.0.0
+ * Authorize config before opening the service pipe
+ * Remove dependence on pathcch.dll not in Windows 7
* Included win-dco driver updated to 2.8.0
| | | |
|-|-|-|
- |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc2-I009-amd64.msi.asc)|[OpenVPN-2.7_rc2-I009-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc2-I009-amd64.msi)|
- |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc2-I009-arm64.msi.asc)|[OpenVPN-2.7_rc2-I009-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc2-I009-arm64.msi)|
- |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc2-I009-x86.msi.asc)|[OpenVPN-2.7_rc2-I009-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc2-I009-x86.msi)|
- |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc2.tar.gz.asc)|[openvpn-2.7_rc2.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc2.tar.gz)|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc3-I010-amd64.msi.asc)|[OpenVPN-2.7_rc3-I010-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc3-I010-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc3-I010-arm64.msi.asc)|[OpenVPN-2.7_rc3-I010-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc3-I010-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc3-I010-x86.msi.asc)|[OpenVPN-2.7_rc3-I010-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc3-I010-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc3.tar.gz.asc)|[openvpn-2.7_rc3.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc3.tar.gz)|
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
- ## OpenVPN 2.6.16 -- Released 17 November 2025
- The OpenVPN community project team is proud to release OpenVPN 2.6.16. This is a bugfix release containing one security fix.
+ ## OpenVPN 2.6.17 -- Released 28 November 2025
+ The OpenVPN community project team is proud to release OpenVPN 2.6.17. This is a bugfix release containing one security fix.
- For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.16/Changes.rst)
+ For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.17/Changes.rst)
Security fixes:
- * [CVE-2025-13086](https://www.cve.org/CVERecord?id=CVE-2025-13086): Fix memcmp check for the hmac verification in the 3way handshake.
- This bug renders the HMAC based protection against state exhaustion on
- receiving spoofed TLS handshake packets in the OpenVPN server inefficient.
+ * [CVE-2025-13751](https://www.cve.org/CVERecord?id=CVE-2025-13751): Windows/interactive service: fix erroneous exit on error that could be
+ used by a local Windows users to achieve a local denial-of-service
Bug fixes:
- * fix invalid pointer creation in tls_pre_decrypt() - technically this is
- a memory over-read issue, in practice, the compilers optimize it away
- so no negative effects could be observed.
- * Windows: in the interactive service, fix the "undo DNS config" handling.
- * Windows: in the interactive service, disallow using of "stdin" for the
- config file, unless the caller is authorized OpenVPN Administrator
- * Windows: in the interactive service, change all netsh calls to use
- interface index and not interface name - sidesteps all possible attack
- avenues with special characters in interface names.
- * Windows: in the interactive service, improve error handling in
- some "unlikely to happen" paths.
- * auth plugin/script handling: properly check for errors in creation on
- $auth_failed_reason_file (arf).
- * for incoming TCP connections, close-on-exec option was applied to
- the wrong socket fd, leaking socket FDs to child processes.
- * sitnl: set close-on-exec flag on netlink socket
- * ssl_mbedtls: fix missing perf_pop() call (optional performance profiling)
-
- Windows MSI changes since 2.6.15-I001:
+ * Windows/interactive service: improve service pipe robustness against
+ file access races (uuid) and access by unauthorized processes (ACL).
+ * upgrade bundled build instruction (vcpkg and patch) for pkcs11-helper
+ to 1.31, fixing a parser bug
+
+ Windows MSI changes since 2.6.16-I001:
* Built against OpenSSL 3.6.0
- * Included openvpn-gui updated to 11.58.0.0
- * Check the return value of GetProp()
- * Make config path check similar to that in interactive service
- * Escape the type id of password message received from openvpn
- * Add a message source for event logging
- * Check correct management daemon path when OpenVPN3 is enabled
- * Fix OpenVPN3 radio button label size when OVPN3 is enabled
- * Use GetTempPath() for debug file in plap as well
- * Migrate all saved plain usernames to encrypted format
+ * Included openvpn-gui updated to 11.59.0.0
+ * Authorize config before opening the service pipe
+ * Remove dependence on pathcch.dll not in Windows 7
* Included win-dco driver updated to 2.8.0
| | | |
|-|-|-|
- |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.16-I001-amd64.msi.asc)|[OpenVPN-2.6.16-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.16-I001-amd64.msi)|
- |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.16-I001-arm64.msi.asc)|[OpenVPN-2.6.16-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.16-I001-arm64.msi)|
- |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.16-I001-x86.msi.asc)|[OpenVPN-2.6.16-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.16-I001-x86.msi)|
- |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.16.tar.gz.asc)|[openvpn-2.6.16.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.16.tar.gz)|
+ |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.17-I001-amd64.msi.asc)|[OpenVPN-2.6.17-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.17-I001-amd64.msi)|
+ |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.17-I001-arm64.msi.asc)|[OpenVPN-2.6.17-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.17-I001-arm64.msi)|
+ |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.17-I001-x86.msi.asc)|[OpenVPN-2.6.17-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.17-I001-x86.msi)|
+ |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.17.tar.gz.asc)|[openvpn-2.6.17.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.17.tar.gz)|
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9