Blame

ef2447 uddr 2026-09-03 14:33:00 1
## OpenVPN 2.7.7 -- Released 3 September 2026
2
The OpenVPN community project team is proud to release OpenVPN 2.7.7. This is a bugfix release fixing
3
many security issues.
39396b flichtenheld 2026-07-01 13:37:52 4
ef2447 uddr 2026-09-03 14:33:00 5
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7.7/Changes.rst)
39396b flichtenheld 2026-07-01 13:37:52 6
7
Security fixes:
8
ef2447 uddr 2026-09-03 14:33:00 9
- reliability layer: avoid unbounded reliable TLS timeout, and ignore acks
10
for packets that cannot be outstanding ([CVE-2026-84732](https://www.cve.org/CVERecord?id=CVE-2026-84732))
39396b flichtenheld 2026-07-01 13:37:52 11
ef2447 uddr 2026-09-03 14:33:00 12
Both reliability layer bugs found by Mark Bregman (Fox-IT), tracked in
13
Github: OpenVPN/openvpn-private-issues#161
8b6955 flichtenheld 2026-08-05 14:28:29 14
ef2447 uddr 2026-09-03 14:33:00 15
- windows: fix `CreateProcess()` command line quoting for characters that
16
are special to `cmd.exe`, where a combination of validation script plus
17
rogue CA could lead to misbehavior ([CVE-2026-84256](https://www.cve.org/CVERecord?id=CVE-2026-84256))
8b6955 flichtenheld 2026-08-05 14:28:29 18
ef2447 uddr 2026-09-03 14:33:00 19
Bug found by Clouditera Security, tracked in Github:
20
OpenVPN/openvpn-private-issues#159
6e939a flichtenheld 2026-07-01 14:44:18 21
ef2447 uddr 2026-09-03 14:33:00 22
- windows: fix `tapctl` to always call `netsh.exe` with full path
23
(as we do elsewhere) ([CVE-2026-84226](https://www.cve.org/CVERecord?id=CVE-2026-84226))
39396b flichtenheld 2026-07-01 13:37:52 24
ef2447 uddr 2026-09-03 14:33:00 25
Bug found by BreachX Zero Day Labs (using Typhon AI Mil v2), tracked in
26
Github: OpenVPN/openvpn-private-issues#164
39396b flichtenheld 2026-07-01 13:37:52 27
ef2447 uddr 2026-09-03 14:33:00 28
- windows: don't use NULL DACL with system objects, namely the `--service`
29
exit event and the `netsh.exe` guard semaphore. The old approach was
30
prone to a local DoS where one user could interfere with other users'
31
openvpn processes by blocking the netsh semaphore or sending events.
32
This only affects setups not using the iservice, or using the automatic
33
service to start/stop openvpn ([CVE-2026-82312](https://www.cve.org/CVERecord?id=CVE-2026-82312))
39396b flichtenheld 2026-07-01 13:37:52 34
ef2447 uddr 2026-09-03 14:33:00 35
Bug found by DEBRAJ BASAK, tracked in Github:
36
OpenVPN/openvpn-private-issues#167
39396b flichtenheld 2026-07-01 13:37:52 37
ef2447 uddr 2026-09-03 14:33:00 38
- openvpnserv (windows): pass correct NRPT domains size - when IDN domains
39
with UTF8 encoding were involved, a buffer overread could be achieved
40
([CVE-2026-78221](https://www.cve.org/CVERecord?id=CVE-2026-78221))
41
42
Bug found by BreachX Zero Day Labs (using Typhon AI Mil v2), in Github:
43
OpenVPN/openvpn-private-issues#162
44
45
- openvpnserv (windows): don't allow '/' in config paths. The APIs windows
46
uses for path validation do not handle '/' as path separator, while the
47
file open APIs do, so this could be used to circumvent our config path
48
validation, leading to openvpn.exe starting a user-controlled config file
49
even if administratively not allowed ([CVE-2026-78043](https://www.cve.org/CVERecord?id=CVE-2026-78043))
50
51
Bug found by BreachX Zero Day Labs (using Typhon AI Mil v2), in Github:
52
OpenVPN/openvpn-private-issues#162
53
54
- dhcp (windows): fix off-by-one in `write_dhcp_search_str()` temp buffer
55
guard - suitable DHCP options could lead to a single-byte overflow of a
56
temp buffer ([CVE-2026-81738](https://www.cve.org/CVERecord?id=CVE-2026-81738))
57
58
Bug found by Andre Kropp (Nexory) and ChinhNguyen, tracked in Github:
59
OpenVPN/openvpn-private-issues#165
39396b flichtenheld 2026-07-01 13:37:52 60
ef2447 uddr 2026-09-03 14:33:00 61
- linux netlink: validate netlink replies against the request
39396b flichtenheld 2026-07-01 13:37:52 62
ef2447 uddr 2026-09-03 14:33:00 63
Suggested by Joshua Rogers as a security improvement, tracked in Github:
64
OpenVPN/openvpn-private-issues#9
39396b flichtenheld 2026-07-01 13:37:52 65
ef2447 uddr 2026-09-03 14:33:00 66
- openvpnserv (windows): fix off-by-one on input validation
67
(discovered while fixing CVE-2026-78221)
39396b flichtenheld 2026-07-01 13:37:52 68
ef2447 uddr 2026-09-03 14:33:00 69
- openvpnserv (windows): harden `CheckConfigPath()` a bit more
70
(another improvement while working on CVE-2026-78043)
71
72
User-visible Changes:
73
74
- when using EPOCH data channel format, reduce the number of future keys
75
from 16 to 4 - the previous calculation was wrong, and 4 spare keys are
76
sufficient for 100+ Gbit/s links. This means less log spam in userland
77
and fewer resources used in in-kernel implementations.
8b6955 flichtenheld 2026-08-05 14:28:29 78
79
Bugfixes:
39396b flichtenheld 2026-07-01 13:37:52 80
ef2447 uddr 2026-09-03 14:33:00 81
- work around a pubkey-handling bug in mbedTLS 4.1.0 and 4.2.0
82
(supposedly fixed in 4.3.0)
83
84
- multi: don't let stale-routes-check delete permanent routes -
85
`--stale-routes-check` did not only delete dynamic cached routes, but
86
also routes installed by `--iroute` and `--ifconfig-push`. Fixed by
87
introducing route flags and restraining the check on them
88
(Github: [OpenVPN/openvpn#1063](https://github.com/OpenVPN/openvpn/issues/1063))
89
90
- ssl: do not queue control ciphertext while a packet is still queued
91
(fixes problems in TCP p2p handshake when both sides try to handshake
92
at the same time)
93
(Github: [OpenVPN/openvpn#1089](https://github.com/OpenVPN/openvpn/issues/1089))
94
95
- reenable xmit_hold when using p2p tcp-server and tls-server - in TCP
96
server mode the server is not expected to initiate the TLS handshake.
97
This was introduced by the multisocket code checking the wrong variable
98
for socket protocol
99
(Github: [OpenVPN/openvpn#1089](https://github.com/OpenVPN/openvpn/issues/1089))
100
101
- clinat: do not adjust UDP checksum if zero (as per RFC768)
102
(Github: [OpenVPN/openvpn#1037](https://github.com/OpenVPN/openvpn/issues/1037))
39396b flichtenheld 2026-07-01 13:37:52 103
ef2447 uddr 2026-09-03 14:33:00 104
- openssl: avoid resetting the HMAC key on every packet
105
(Github: [OpenVPN/openvpn#1088](https://github.com/OpenVPN/openvpn/issues/1088))
39396b flichtenheld 2026-07-01 13:37:52 106
ef2447 uddr 2026-09-03 14:33:00 107
- openvpnserv (windows): fix log lines format string - interface names with
108
international characters printed in some error messages need to be
109
converted from UTF8 to UCS16 first.
39396b flichtenheld 2026-07-01 13:37:52 110
ef2447 uddr 2026-09-03 14:33:00 111
- fix format string specifier for size_t (%zu)
6e939a flichtenheld 2026-07-01 14:44:18 112
ef2447 uddr 2026-09-03 14:33:00 113
- fix test_misc compile issues with -Werror
c8181c flichtenheld 2026-06-10 16:39:29 114
ef2447 uddr 2026-09-03 14:33:00 115
Windows MSI changes since 2.7.6-I001:
116
* Update included dco-win driver to v2.8.7
778b33 uddr 2026-09-07 09:55:08 117
* peer: fix use-after-free in multipeer peer table handling (Github: [OpenVPN/ovpn-dco-win#140](https://github.com/OpenVPN/ovpn-dco-win/pull/140))([CVE-2026-82325](https://www.cve.org/CVERecord?id=CVE-2026-82325))
118
* inf: set the device security descriptor in the hardware key (Github: [OpenVPN/ovpn-dco-win#139](https://github.com/OpenVPN/ovpn-dco-win/pull/139))
21a0aa flichtenheld 2026-03-31 15:00:25 119
99ee06 flichtenheld 2025-07-31 19:24:29 120
| | | |
121
|-|-|-|
ef2447 uddr 2026-09-03 14:33:00 122
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-amd64.msi.asc)|[OpenVPN-2.7.7-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-amd64.msi)|
123
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-arm64.msi.asc)|[OpenVPN-2.7.7-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-arm64.msi)|
124
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-x86.msi.asc)|[OpenVPN-2.7.7-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-x86.msi)|
125
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7.7.tar.gz.asc)|[openvpn-2.7.7.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7.7.tar.gz)|
99ee06 flichtenheld 2025-07-31 19:24:29 126
21a0aa flichtenheld 2026-03-31 15:00:25 127
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
687bbf novaflash 2025-06-20 17:21:18 128
30bd51 uddr 2026-09-23 14:18:40 129
## OpenVPN 2.6.23 -- Released 23 September 2026
130
The OpenVPN community project team is proud to release OpenVPN 2.6.23. This is a bugfix release fixing
8a81ee flichtenheld 2026-07-01 14:35:40 131
several security issues.
23ddda flichtenheld 2026-02-04 14:22:30 132
d2738c flichtenheld 2026-08-06 15:19:11 133
> [!IMPORTANT]
557498 flichtenheld 2026-09-23 16:01:44 134
> After 2.6.22 release the [support status](../Pages/Supported%20versions) of OpenVPN 2.6 changed from "Full Support" to "Old Stable Support".
135
> This means that we do not provide Windows installer downloads of future 2.6.x releases.
d2738c flichtenheld 2026-08-06 15:19:11 136
30bd51 uddr 2026-09-23 14:18:40 137
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.23/Changes.rst)
485d55 flichtenheld 2026-02-04 18:03:20 138
a92ca4 uddr 2026-04-22 15:02:45 139
Security fixes:
23ddda flichtenheld 2026-02-04 14:22:30 140
30bd51 uddr 2026-09-23 14:18:40 141
- ssl: do not trust the peer's request to resend the wrapped client key
8a81ee flichtenheld 2026-07-01 14:35:40 142
30bd51 uddr 2026-09-23 14:18:40 143
Tracked in Github: OpenVPN/openvpn-private-issues#181
6e939a flichtenheld 2026-07-01 14:44:18 144
30bd51 uddr 2026-09-23 14:18:40 145
- reliability layer: avoid unbounded reliable TLS timeout, and ignore acks
146
for packets that cannot be outstanding ([CVE-2026-84732](https://www.cve.org/CVERecord?id=CVE-2026-84732))
8a81ee flichtenheld 2026-07-01 14:35:40 147
30bd51 uddr 2026-09-23 14:18:40 148
Both reliability layer bugs found by Mark Bregman (Fox-IT), tracked in
149
Github: OpenVPN/openvpn-private-issues#161
8a81ee flichtenheld 2026-07-01 14:35:40 150
30bd51 uddr 2026-09-23 14:18:40 151
- improve on `check_session_buf_not_used()`, catch possible double-free in
152
the lame duck case ([CVE-2026-84471](https://www.cve.org/CVERecord?id=CVE-2026-84471))
8a81ee flichtenheld 2026-07-01 14:35:40 153
30bd51 uddr 2026-09-23 14:18:40 154
Bug reported by Andreas Gabriel Berbescu, tracked in Github:
155
OpenVPN/openvpn-private-issues#157, and by Haruki Oyama (Waseda
156
University), tracked in OpenVPN/openvpn-private-issues#132
f8247c flichtenheld 2026-08-05 19:37:38 157
30bd51 uddr 2026-09-23 14:18:40 158
- windows: fix `CreateProcess()` command line quoting for characters that
159
are special to `cmd.exe`, where a combination of validation script plus
160
rogue CA could lead to misbehavior ([CVE-2026-84256](https://www.cve.org/CVERecord?id=CVE-2026-84256))
f8247c flichtenheld 2026-08-05 19:37:38 161
30bd51 uddr 2026-09-23 14:18:40 162
Bug found by Clouditera Security, tracked in Github:
163
OpenVPN/openvpn-private-issues#159
f8247c flichtenheld 2026-08-05 19:37:38 164
30bd51 uddr 2026-09-23 14:18:40 165
- windows: fix `tapctl` to always call `netsh.exe` with full path
166
(as we do elsewhere) ([CVE-2026-84226](https://www.cve.org/CVERecord?id=CVE-2026-84226))
8a81ee flichtenheld 2026-07-01 14:35:40 167
30bd51 uddr 2026-09-23 14:18:40 168
Bug found by BreachX Zero Day Labs (using Typhon AI Mil v2), tracked in
169
Github: OpenVPN/openvpn-private-issues#164
170
171
- windows: don't use NULL DACL with system objects, namely the `--service`
172
exit event and the `netsh.exe` guard semaphore. The old approach was
173
prone to a local DoS where one user could interfere with other users'
174
openvpn processes by blocking the netsh semaphore or sending events.
175
This only affects setups not using the iservice, or using the automatic
176
service to start/stop openvpn ([CVE-2026-82312](https://www.cve.org/CVERecord?id=CVE-2026-82312))
177
178
Bug found by DEBRAJ BASAK, tracked in Github:
179
OpenVPN/openvpn-private-issues#167
180
181
- dhcp (windows): fix off-by-one in `write_dhcp_search_str()` temp buffer
182
guard - suitable DHCP options could lead to a single-byte overflow of a
183
temp buffer ([CVE-2026-81738](https://www.cve.org/CVERecord?id=CVE-2026-81738))
184
185
Bug found by Andre Kropp (Nexory) and ChinhNguyen, tracked in Github:
186
OpenVPN/openvpn-private-issues#165
187
188
- openvpnserv (windows): detect and refuse sibling dirs in
189
`CheckConfigPath()` ([CVE-2026-81830](https://www.cve.org/CVERecord?id=CVE-2026-81830))
190
191
Bug found by Harshit Varu, tracked in Github:
192
OpenVPN/openvpn-private-issues#166
8a81ee flichtenheld 2026-07-01 14:35:40 193
4b4a8b uddr 2025-06-20 13:43:39 194
| | | |
195
|-|-|-|
30bd51 uddr 2026-09-23 14:18:40 196
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.23.tar.gz.asc)|[openvpn-2.6.23.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.23.tar.gz)|
4b4a8b uddr 2025-06-20 13:43:39 197
ecf3c7 uddr 2025-11-17 14:47:15 198
#### [Full Release History](https://community.openvpn.net/ReleaseHistory)