OpenVPN 2.7_rc2 -- Released 17 November 2025

The OpenVPN community project team is proud to release OpenVPN 2.7_rc2. This is the second release candidate for the feature release 2.7.0.

Security fixes:

  • CVE-2025-12106: IPv6 address parsing: fix buffer overread on invalid input
  • CVE-2025-13086: HMAC verification check: fix incorrect memcmp() call

Important bug fixes since 2.7_rc1:

  • even more type conversion related warnings have been fixed
  • DCO FreeBSD improvements:
    • improving debug messages (verb 6)
    • implement client-side counter handling
    • repair --inactive (and document shortcomings)
    • repair handling of DCO disconnection notifications in --client mode
  • Windows/Service improvements, hardening, bugfixes
    • fix DNS address list generation (if 3 or more --dns addresses in use)
    • fix DNS server undo_list
    • disallow "stdin" as config name unless user has OpenVPN admin privs
    • fix compilation errors with MSVC v19
    • iservice: improve validation of config path (pathcc lib)
      • [NOTE: this breaks OpenVPN compatibility with Windows 7]
    • tapctl: refactor, improve output, change driver default to ovpn-dco
    • iservice: when restoring iface metrics, enforce correct ifindex
  • improve cmocka unit test assert() handling
  • PUSH_UPDATE server: fix reporting of client IPs in status output after pushing a new IPv4/IPv6 address to client
  • AEAD cipher safety margins: fix calculation of AEAD blocks in use (old code would undercount blocks)
  • fix invalid pointer creation / memory overread in tls_pre_decrypt
  • deprecate --opt-verify (change into no-op + warning)

For a list of all changes see the git log.

Highlights of 2.7 include:

  • Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
  • Improved Client support for DNS options
    • Client implementations for Linux/BSD/macOS, included with the default install
    • New client implementation for Windows, adding support for features like split DNS and DNSSEC
  • Architectural improvements on Windows
    • The block-local flag is now enforced with WFP filters
    • Windows network adapters are now generated on demand
    • Windows automatic service now runs as an unpriviledged user
    • Support for server mode in win-dco driver
    • Note: Support for the wintun driver has been removed. win-dco is now the default, tap-windows6 is the fallback solution for use-cases not covered by win-dco.
  • Improved data channel
    • Enforcement of AES-GCM usage limit
    • Epoch data keys and packet format
  • Support for new upstream DCO Linux kernel module
    • This release supports the new ovpn DCO Linux kernel module which will be available in future upstream Linux kernel releases. Backports of the new module to current kernels are available via the ovpn-backports project.
  • Client-side support for new PUSH_UPDATE control-channel message
    • This allows servers to send updates to options like routing and DNS config without triggering a reconnect.
  • PUSH_UPDATE server support (minimal)
    • New management interface commands push-update-broad and push-update-cid to send PUSH_UPDATE option updates.
  • TLS 1.3 support with bleeding-edge mbedTLS versions
  • Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
  • Support for Epoch data channel on Windows, using the win-dco driver (2.8.0+)
  • "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
  • COPYING: license details only relevant to our Windows installers have been updated and moved to the openvpn-build repo

For details see Changes.rst

Windows MSI changes since 2.7_rc1:

  • Built against OpenSSL 3.6.0
  • Included openvpn-gui updated to 11.58.0.0
    • Check the return value of GetProp()
    • Make config path check similar to that in interactive service
    • Escape the type id of password message received from openvpn
    • Add a message source for event logging
    • Check correct management daemon path when OpenVPN3 is enabled
    • Fix OpenVPN3 radio button label size when OVPN3 is enabled
    • Use GetTempPath() for debug file in plap as well
    • Migrate all saved plain usernames to encrypted format
  • Included win-dco driver updated to 2.8.0
Windows 64-bit MSI installer GnuPG Signature OpenVPN-2.7_rc2-I009-amd64.msi
Windows ARM64 MSI installer GnuPG Signature OpenVPN-2.7_rc2-I009-arm64.msi
Windows 32-bit MSI installer GnuPG Signature OpenVPN-2.7_rc2-I009-x86.msi
Source archive file GnuPG Signature openvpn-2.7_rc2.tar.gz

For Community-maintained packages for Linux distributions see OpenVPN Software Repositories. Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.

OpenVPN 2.6.16 -- Released 17 November 2025

The OpenVPN community project team is proud to release OpenVPN 2.6.16. This is a bugfix release containing one security fix.

For details see Changes.rst

Security fixes:

  • CVE-2025-13086: Fix memcmp check for the hmac verification in the 3way handshake. This bug renders the HMAC based protection against state exhaustion on receiving spoofed TLS handshake packets in the OpenVPN server inefficient.

Bug fixes:

  • fix invalid pointer creation in tls_pre_decrypt() - technically this is a memory over-read issue, in practice, the compilers optimize it away so no negative effects could be observed.
  • Windows: in the interactive service, fix the "undo DNS config" handling.
  • Windows: in the interactive service, disallow using of "stdin" for the config file, unless the caller is authorized OpenVPN Administrator
  • Windows: in the interactive service, change all netsh calls to use interface index and not interface name - sidesteps all possible attack avenues with special characters in interface names.
  • Windows: in the interactive service, improve error handling in some "unlikely to happen" paths.
  • auth plugin/script handling: properly check for errors in creation on $auth_failed_reason_file (arf).
  • for incoming TCP connections, close-on-exec option was applied to the wrong socket fd, leaking socket FDs to child processes.
  • sitnl: set close-on-exec flag on netlink socket
  • ssl_mbedtls: fix missing perf_pop() call (optional performance profiling)

Windows MSI changes since 2.6.15-I001:

  • Built against OpenSSL 3.6.0
  • Included openvpn-gui updated to 11.58.0.0
    • Check the return value of GetProp()
    • Make config path check similar to that in interactive service
    • Escape the type id of password message received from openvpn
    • Add a message source for event logging
    • Check correct management daemon path when OpenVPN3 is enabled
    • Fix OpenVPN3 radio button label size when OVPN3 is enabled
    • Use GetTempPath() for debug file in plap as well
    • Migrate all saved plain usernames to encrypted format
  • Included win-dco driver updated to 2.8.0
Windows 64-bit MSI installer GnuPG Signature OpenVPN-2.6.16-I001-amd64.msi
Windows ARM64 MSI installer GnuPG Signature OpenVPN-2.6.16-I001-arm64.msi
Windows 32-bit MSI installer GnuPG Signature OpenVPN-2.6.16-I001-x86.msi
Source archive file GnuPG Signature openvpn-2.6.16.tar.gz

For Community-maintained packages for Linux distributions see OpenVPN Software Repositories.

OpenVPN 2.5.9 -- Released 15 February 2023

The OpenVPN community project team is proud to release OpenVPN 2.5.9. This is a small bugfix release.

For details see Changes.rst

Windows MSI changes since 2.5.8:

  • Build against OpenSSL 1.1.1t which contains several security fixes.
Windows 64-bit MSI installer GnuPG Signature OpenVPN-2.5.9-I601-amd64.msi
Windows ARM64 MSI installer GnuPG Signature OpenVPN-2.5.9-I601-arm64.msi
Windows 32-bit MSI installer GnuPG Signature OpenVPN-2.5.9-I601-x86.msi
Source archive file GnuPG Signature openvpn-2.5.9.tar.gz

Full Release History