* fix DNS address list generation (if 3 or more --dns addresses in use)
-
* fix DNS server undo_list
-
* disallow "stdin" as config name unless user has OpenVPN admin privs
-
* fix compilation errors with MSVC v19
-
* iservice: improve validation of config path (pathcc lib)
-
* [NOTE: this breaks OpenVPN compatibility with Windows 7]
-
* tapctl: refactor, improve output, change driver default to ovpn-dco
-
* iservice: when restoring iface metrics, enforce correct ifindex
-
* improve cmocka unit test assert() handling
-
* PUSH_UPDATE server: fix reporting of client IPs in ``status`` output after pushing a new IPv4/IPv6 address to client
-
* AEAD cipher safety margins: fix calculation of AEAD blocks in use (old code would undercount blocks)
-
* fix invalid pointer creation / memory overread in tls_pre_decrypt
-
* deprecate ``--opt-verify`` (change into no-op + warning)
-
-
For a list of all changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_rc1...v2.7_rc2).
+
* [CVE-2025-13751](https://www.cve.org/CVERecord?id=CVE-2025-13751): Windows/interactive service: fix bug where the interactive service would error-exit in
+
certain error conditions instead of just logging the fact and
+
continuing. After the error-exit, OpenVPN connections will no
+
longer work until the service is restarted (or the system rebooted).
+
This can be triggered by any authenticated local user, and has
+
thus been classified as a "local denial of service" attack.
+
+
Important bug fixes since 2.7_rc2:
+
* Windows/Interactive Service bugfixes:
+
many small bugfixes to registry-related DNS domain handling
+
* Windows/Interactive Service: harden service pipe handling
+
close a small race condition, and add restrictive ACLs
+
* more type conversion related warnings have been fixed
+
* --multihome behaviour regarding egress interface selection has been
+
changed. See Changes.rst and manpage for details.
+
* cleanup dead code in event handling code (leftover of the multisocket
+
patch set)
+
* add new feature, --tls-crypt-v2-max-age n. See Changes.rst and
+
manpage for details.
+
* improve documentation to point out the pitfalls of case-insensitive
+
filesystems and --client-config-dir
+
* split default gateway query logic in two:
+
* for --redirect-gateway functionality, query for the gateway towards
+
the actual IP address of the VPN server connecting to
+
* for the "net_gateway" special destination for --route, and the
+
corresponding environment variable, always query for 0.0.0.0 / ::
+
(this will only make a difference in certain scenarios using a local
+
proxy, or on a system with multiple interfaces, not using the "default
+
route" for the VPN connection * see github#890)
+
* upgrade embedded pkcs11-helper vcpkg + pkcs11-uri patch to 1.31
* DCO (primarily Linux): improve handling of bulk notifications from
+
kernel (do not lose notifications, do not crash) ([github#900](https://github.com/OpenVPN/openvpn/issues/900))
+
+
For a list of all changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_rc2...v2.7_rc3).
Highlights of 2.7 include:
* Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
@@ 55,80 65,54 @@
* "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
* COPYING: license details only relevant to our Windows installers have been updated and moved to the openvpn-build repo
-
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_rc2/Changes.rst)
+
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_rc3/Changes.rst)
-
Windows MSI changes since 2.7_rc1:
+
Windows MSI changes since 2.7_rc2:
* Built against OpenSSL 3.6.0
-
* Included openvpn-gui updated to 11.58.0.0
-
* Check the return value of GetProp()
-
* Make config path check similar to that in interactive service
-
* Escape the type id of password message received from openvpn
-
* Add a message source for event logging
-
* Check correct management daemon path when OpenVPN3 is enabled
-
* Fix OpenVPN3 radio button label size when OVPN3 is enabled
-
* Use GetTempPath() for debug file in plap as well
-
* Migrate all saved plain usernames to encrypted format
+
* Included openvpn-gui updated to 11.59.0.0
+
* Authorize config before opening the service pipe
+
* Remove dependence on pathcch.dll not in Windows 7
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
-
## OpenVPN 2.6.16 -- Released 17 November 2025
-
The OpenVPN community project team is proud to release OpenVPN 2.6.16. This is a bugfix release containing one security fix.
+
## OpenVPN 2.6.17 -- Released 28 November 2025
+
The OpenVPN community project team is proud to release OpenVPN 2.6.17. This is a bugfix release containing one security fix.
-
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.16/Changes.rst)
+
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.17/Changes.rst)
Security fixes:
-
* [CVE-2025-13086](https://www.cve.org/CVERecord?id=CVE-2025-13086): Fix memcmp check for the hmac verification in the 3way handshake.
-
This bug renders the HMAC based protection against state exhaustion on
-
receiving spoofed TLS handshake packets in the OpenVPN server inefficient.
+
* [CVE-2025-13751](https://www.cve.org/CVERecord?id=CVE-2025-13751): Windows/interactive service: fix erroneous exit on error that could be
+
used by a local Windows users to achieve a local denial-of-service
Bug fixes:
-
* fix invalid pointer creation in tls_pre_decrypt() - technically this is
-
a memory over-read issue, in practice, the compilers optimize it away
-
so no negative effects could be observed.
-
* Windows: in the interactive service, fix the "undo DNS config" handling.
-
* Windows: in the interactive service, disallow using of "stdin" for the
-
config file, unless the caller is authorized OpenVPN Administrator
-
* Windows: in the interactive service, change all netsh calls to use
-
interface index and not interface name - sidesteps all possible attack
-
avenues with special characters in interface names.
-
* Windows: in the interactive service, improve error handling in
-
some "unlikely to happen" paths.
-
* auth plugin/script handling: properly check for errors in creation on
-
$auth_failed_reason_file (arf).
-
* for incoming TCP connections, close-on-exec option was applied to
-
the wrong socket fd, leaking socket FDs to child processes.