Blame

ded534 uddr 2026-09-23 14:19:48 1
## OpenVPN 2.6.23 -- Released 23 September 2026
2
The OpenVPN community project team is proud to release OpenVPN 2.6.23. This is a bugfix release fixing
3
several security issues.
4
5
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.23/Changes.rst)
6
7
Security fixes:
8
9
- ssl: do not trust the peer's request to resend the wrapped client key
10
11
Tracked in Github: OpenVPN/openvpn-private-issues#181
12
13
- reliability layer: avoid unbounded reliable TLS timeout, and ignore acks
14
for packets that cannot be outstanding ([CVE-2026-84732](https://www.cve.org/CVERecord?id=CVE-2026-84732))
15
16
Both reliability layer bugs found by Mark Bregman (Fox-IT), tracked in
17
Github: OpenVPN/openvpn-private-issues#161
18
19
- improve on `check_session_buf_not_used()`, catch possible double-free in
20
the lame duck case ([CVE-2026-84471](https://www.cve.org/CVERecord?id=CVE-2026-84471))
21
22
Bug reported by Andreas Gabriel Berbescu, tracked in Github:
23
OpenVPN/openvpn-private-issues#157, and by Haruki Oyama (Waseda
24
University), tracked in OpenVPN/openvpn-private-issues#132
25
26
- windows: fix `CreateProcess()` command line quoting for characters that
27
are special to `cmd.exe`, where a combination of validation script plus
28
rogue CA could lead to misbehavior ([CVE-2026-84256](https://www.cve.org/CVERecord?id=CVE-2026-84256))
29
30
Bug found by Clouditera Security, tracked in Github:
31
OpenVPN/openvpn-private-issues#159
32
33
- windows: fix `tapctl` to always call `netsh.exe` with full path
34
(as we do elsewhere) ([CVE-2026-84226](https://www.cve.org/CVERecord?id=CVE-2026-84226))
35
36
Bug found by BreachX Zero Day Labs (using Typhon AI Mil v2), tracked in
37
Github: OpenVPN/openvpn-private-issues#164
38
39
- windows: don't use NULL DACL with system objects, namely the `--service`
40
exit event and the `netsh.exe` guard semaphore. The old approach was
41
prone to a local DoS where one user could interfere with other users'
42
openvpn processes by blocking the netsh semaphore or sending events.
43
This only affects setups not using the iservice, or using the automatic
44
service to start/stop openvpn ([CVE-2026-82312](https://www.cve.org/CVERecord?id=CVE-2026-82312))
45
46
Bug found by DEBRAJ BASAK, tracked in Github:
47
OpenVPN/openvpn-private-issues#167
48
49
- dhcp (windows): fix off-by-one in `write_dhcp_search_str()` temp buffer
50
guard - suitable DHCP options could lead to a single-byte overflow of a
51
temp buffer ([CVE-2026-81738](https://www.cve.org/CVERecord?id=CVE-2026-81738))
52
53
Bug found by Andre Kropp (Nexory) and ChinhNguyen, tracked in Github:
54
OpenVPN/openvpn-private-issues#165
55
56
- openvpnserv (windows): detect and refuse sibling dirs in
57
`CheckConfigPath()` ([CVE-2026-81830](https://www.cve.org/CVERecord?id=CVE-2026-81830))
58
59
Bug found by Harshit Varu, tracked in Github:
60
OpenVPN/openvpn-private-issues#166
61
62
| | | |
63
|-|-|-|
64
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.23.tar.gz.asc)|[openvpn-2.6.23.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.23.tar.gz)|
65
c19644 uddr 2026-09-03 14:34:10 66
## OpenVPN 2.7.7 -- Released 3 September 2026
67
The OpenVPN community project team is proud to release OpenVPN 2.7.7. This is a bugfix release fixing
68
many security issues.
69
70
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7.7/Changes.rst)
71
72
Security fixes:
73
74
- reliability layer: avoid unbounded reliable TLS timeout, and ignore acks
75
for packets that cannot be outstanding ([CVE-2026-84732](https://www.cve.org/CVERecord?id=CVE-2026-84732))
76
77
Both reliability layer bugs found by Mark Bregman (Fox-IT), tracked in
78
Github: OpenVPN/openvpn-private-issues#161
79
80
- windows: fix `CreateProcess()` command line quoting for characters that
81
are special to `cmd.exe`, where a combination of validation script plus
82
rogue CA could lead to misbehavior ([CVE-2026-84256](https://www.cve.org/CVERecord?id=CVE-2026-84256))
83
84
Bug found by Clouditera Security, tracked in Github:
85
OpenVPN/openvpn-private-issues#159
86
87
- windows: fix `tapctl` to always call `netsh.exe` with full path
88
(as we do elsewhere) ([CVE-2026-84226](https://www.cve.org/CVERecord?id=CVE-2026-84226))
89
90
Bug found by BreachX Zero Day Labs (using Typhon AI Mil v2), tracked in
91
Github: OpenVPN/openvpn-private-issues#164
92
93
- windows: don't use NULL DACL with system objects, namely the `--service`
94
exit event and the `netsh.exe` guard semaphore. The old approach was
95
prone to a local DoS where one user could interfere with other users'
96
openvpn processes by blocking the netsh semaphore or sending events.
97
This only affects setups not using the iservice, or using the automatic
98
service to start/stop openvpn ([CVE-2026-82312](https://www.cve.org/CVERecord?id=CVE-2026-82312))
99
100
Bug found by DEBRAJ BASAK, tracked in Github:
101
OpenVPN/openvpn-private-issues#167
102
103
- openvpnserv (windows): pass correct NRPT domains size - when IDN domains
104
with UTF8 encoding were involved, a buffer overread could be achieved
105
([CVE-2026-78221](https://www.cve.org/CVERecord?id=CVE-2026-78221))
106
107
Bug found by BreachX Zero Day Labs (using Typhon AI Mil v2), in Github:
108
OpenVPN/openvpn-private-issues#162
109
110
- openvpnserv (windows): don't allow '/' in config paths. The APIs windows
111
uses for path validation do not handle '/' as path separator, while the
112
file open APIs do, so this could be used to circumvent our config path
113
validation, leading to openvpn.exe starting a user-controlled config file
114
even if administratively not allowed ([CVE-2026-78043](https://www.cve.org/CVERecord?id=CVE-2026-78043))
115
116
Bug found by BreachX Zero Day Labs (using Typhon AI Mil v2), in Github:
117
OpenVPN/openvpn-private-issues#162
118
119
- dhcp (windows): fix off-by-one in `write_dhcp_search_str()` temp buffer
120
guard - suitable DHCP options could lead to a single-byte overflow of a
121
temp buffer ([CVE-2026-81738](https://www.cve.org/CVERecord?id=CVE-2026-81738))
122
123
Bug found by Andre Kropp (Nexory) and ChinhNguyen, tracked in Github:
124
OpenVPN/openvpn-private-issues#165
125
126
- linux netlink: validate netlink replies against the request
127
128
Suggested by Joshua Rogers as a security improvement, tracked in Github:
129
OpenVPN/openvpn-private-issues#9
130
131
- openvpnserv (windows): fix off-by-one on input validation
132
(discovered while fixing CVE-2026-78221)
133
134
- openvpnserv (windows): harden `CheckConfigPath()` a bit more
135
(another improvement while working on CVE-2026-78043)
136
137
User-visible Changes:
138
139
- when using EPOCH data channel format, reduce the number of future keys
140
from 16 to 4 - the previous calculation was wrong, and 4 spare keys are
141
sufficient for 100+ Gbit/s links. This means less log spam in userland
142
and fewer resources used in in-kernel implementations.
143
144
Bugfixes:
145
146
- work around a pubkey-handling bug in mbedTLS 4.1.0 and 4.2.0
147
(supposedly fixed in 4.3.0)
148
149
- multi: don't let stale-routes-check delete permanent routes -
150
`--stale-routes-check` did not only delete dynamic cached routes, but
151
also routes installed by `--iroute` and `--ifconfig-push`. Fixed by
152
introducing route flags and restraining the check on them
153
(Github: [OpenVPN/openvpn#1063](https://github.com/OpenVPN/openvpn/issues/1063))
154
155
- ssl: do not queue control ciphertext while a packet is still queued
156
(fixes problems in TCP p2p handshake when both sides try to handshake
157
at the same time)
158
(Github: [OpenVPN/openvpn#1089](https://github.com/OpenVPN/openvpn/issues/1089))
159
160
- reenable xmit_hold when using p2p tcp-server and tls-server - in TCP
161
server mode the server is not expected to initiate the TLS handshake.
162
This was introduced by the multisocket code checking the wrong variable
163
for socket protocol
164
(Github: [OpenVPN/openvpn#1089](https://github.com/OpenVPN/openvpn/issues/1089))
165
166
- clinat: do not adjust UDP checksum if zero (as per RFC768)
167
(Github: [OpenVPN/openvpn#1037](https://github.com/OpenVPN/openvpn/issues/1037))
168
169
- openssl: avoid resetting the HMAC key on every packet
170
(Github: [OpenVPN/openvpn#1088](https://github.com/OpenVPN/openvpn/issues/1088))
171
172
- openvpnserv (windows): fix log lines format string - interface names with
173
international characters printed in some error messages need to be
174
converted from UTF8 to UCS16 first.
175
176
- fix format string specifier for size_t (%zu)
177
178
- fix test_misc compile issues with -Werror
179
180
Windows MSI changes since 2.7.6-I001:
181
* Update included dco-win driver to v2.8.7
88dbb7 uddr 2026-09-07 09:56:01 182
* peer: fix use-after-free in multipeer peer table handling (Github: [OpenVPN/ovpn-dco-win#140](https://github.com/OpenVPN/ovpn-dco-win/pull/140))([CVE-2026-82325](https://www.cve.org/CVERecord?id=CVE-2026-82325))
183
* inf: set the device security descriptor in the hardware key (Github: [OpenVPN/ovpn-dco-win#139](https://github.com/OpenVPN/ovpn-dco-win/pull/139))
c19644 uddr 2026-09-03 14:34:10 184
185
| | | |
186
|-|-|-|
187
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-amd64.msi.asc)|[OpenVPN-2.7.7-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-amd64.msi)|
188
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-arm64.msi.asc)|[OpenVPN-2.7.7-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-arm64.msi)|
189
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-x86.msi.asc)|[OpenVPN-2.7.7-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-x86.msi)|
190
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7.7.tar.gz.asc)|[openvpn-2.7.7.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7.7.tar.gz)|
191
192
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
193
05fd00 flichtenheld 2026-08-05 19:38:48 194
## OpenVPN 2.7.6 -- Released 5 August 2026
195
The OpenVPN community project team is proud to release OpenVPN 2.7.6. This is a bugfix release fixing
196
several security issues.
197
198
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7.6/Changes.rst)
199
200
Security fixes:
201
202
- openvpnserv (windows): better scrutinize command line passed in
203
from the control socket to openvpn. This would lead to circumventing
204
admin restrictions on allowed openvpn config directories (but never
205
to "read files the user has no permissions for") ([CVE-2026-63649](https://www.cve.org/CVERecord?id=CVE-2026-63649))
206
207
Bug found by 章鱼哥 (www.aipyaipy.com)
208
209
- dco: make key state desync recoverable
210
211
This was reported as a "with suitable timing, a key-update de-sync between
212
OpenVPN and the kernel could trigger an ASSERT()", and was initially
213
handled as security report. It turned out to be not exploitable, but the
214
state machine was not very robust and so the opportunity was used to
215
improve the code.
216
217
Bug found by 章鱼哥 (www.aipyaipy.com)
218
219
- make ``--x509-username-field`` work with mbedTLS.
220
221
In very particular setups, together with a CA creating matching certificates,
222
this could lead to unintentionally permitting a certificate that should
223
not have. This is why this was considered a (low-prio) security bug and a
224
CVE ID was assigned ([CVE-2026-63650](https://www.cve.org/CVERecord?id=CVE-2026-63650))
225
226
Bug found by 章鱼哥 (www.aipyaipy.com)
227
228
User-visible Changes:
229
230
- if `--dev` is not specified, default to `--dev tun` - so for the
231
tun case, this option can now be left out of the openvpn config.
232
233
- `--ping` and `--keepalive` settings are now limited to 24 hours
234
maximum - the primary reason for that is to avoid lots of extra code
235
in the DCO kernel to handle arbitrarily large values without overflowing
236
32 bit integers. 24h is considered much higher than any reasonable use.
237
238
- The `TCP_NODELAY` socket flag is now "always on". The `--tcp-nodelay`
239
option is kept, because setting it on a p2mp server also enables pushing
240
of `socket-flags TCP_NODELAY` to clients, which might not have this
241
code change yet.
242
243
- Remove `--providers` from `--help` output on mbedTLS builds.
244
245
Bugfixes:
246
247
- refuse incoming HARD RESET packets with a sequence ID != 0
248
(this is basically making an OpenVPN server ignore and log a
249
"should never happen" client-side misbehaviour, which could lead to
250
TLS handshake establishment failures in p2p TLS setups)
251
252
- correctly calculate packet id size if epoch packet format is in use -
253
this was off by 4, for connections openvpn 2.7+ to openvpn 2.7+,
254
exceeding "mssfix mtu" headroom by those 4 bytes
255
(Github: [OpenVPN/openvpn#1074](https://github.com/OpenVPN/openvpn/issues/1074))
256
257
- correct minimum packet length check for 802.1q tagged packets
258
(Github: [OpenVPN/openvpn#1044](https://github.com/OpenVPN/openvpn/issues/1044)).
259
260
This was also reported (twice) as a security bug, as technically
261
OpenVPN with `--client-nat` would read and write up to 4 bytes
262
"after the end of the packet" - but due to the OpenVPN packet buffer
263
layouts, which are always full-frame-sized this is fully safe and has
264
no adverse consequences.
265
266
267
Windows MSI changes since 2.7.5-I001:
268
* Update included dco-win driver to v2.8.4
269
* fix control channel stall (Github: [ovpn-dco-win/issues/137](https://github.com/OpenVPN/ovpn-dco-win/issues/137))
270
271
| | | |
272
|-|-|-|
273
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.6-I001-amd64.msi.asc)|[OpenVPN-2.7.6-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.6-I001-amd64.msi)|
274
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.6-I001-arm64.msi.asc)|[OpenVPN-2.7.6-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.6-I001-arm64.msi)|
275
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.6-I001-x86.msi.asc)|[OpenVPN-2.7.6-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.6-I001-x86.msi)|
276
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7.6.tar.gz.asc)|[openvpn-2.7.6.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7.6.tar.gz)|
277
278
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
279
280
## OpenVPN 2.6.22 -- Released 5 August 2026
281
The OpenVPN community project team is proud to release OpenVPN 2.6.22. This is a bugfix release fixing
282
several security issues.
283
284
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.22/Changes.rst)
285
286
Security fixes:
287
288
- openvpnserv (windows): better scrutinize command line passed in
289
from the control socket to openvpn. This would lead to circumventing
290
admin restrictions on allowed openvpn config directories (but never
291
to "read files the user has no permissions for") ([CVE-2026-63649](https://www.cve.org/CVERecord?id=CVE-2026-63649))
292
293
Bug found by 章鱼哥 (www.aipyaipy.com)
294
295
- dco: make key state desync recoverable
296
297
This was reported as a "with suitable timing, a key-update de-sync between
298
OpenVPN and the kernel could trigger an ASSERT()", and was initially
299
handled as security report. It turned out to be not exploitable, but the
300
state machine was not very robust and so the opportunity was used to
301
improve the code.
302
303
Bug found by 章鱼哥 (www.aipyaipy.com)
304
305
Bugfixes:
306
307
- refuse incoming HARD RESET packets with a sequence ID != 0
308
(this is basically making an OpenVPN server ignore and log a
309
"should never happen" client-side misbehaviour, which could lead to
310
TLS handshake establishment failures in p2p TLS setups)
311
312
- correct minimum packet length check for 802.1q tagged packets
313
(Github: [OpenVPN/openvpn#1044](https://github.com/OpenVPN/openvpn/issues/1044)).
314
315
This was also reported (twice) as a security bug, as technically
316
OpenVPN with `--client-nat` would read and write up to 4 bytes
317
"after the end of the packet" - but due to the OpenVPN packet buffer
318
layouts, which are always full-frame-sized this is fully safe and has
319
no adverse consequences.
320
321
322
| | | |
323
|-|-|-|
324
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.22-I001-amd64.msi.asc)|[OpenVPN-2.6.22-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.22-I001-amd64.msi)|
325
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.22-I001-arm64.msi.asc)|[OpenVPN-2.6.22-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.22-I001-arm64.msi)|
326
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.22-I001-x86.msi.asc)|[OpenVPN-2.6.22-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.22-I001-x86.msi)|
327
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.22.tar.gz.asc)|[openvpn-2.6.22.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.22.tar.gz)|
328
329
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
1353e7 flichtenheld 2026-07-01 14:43:01 330
## OpenVPN 2.6.21 -- Released 1 July 2026
331
The OpenVPN community project team is proud to release OpenVPN 2.6.21. This is a bugfix release fixing
332
several security issues.
333
334
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.21/Changes.rst)
335
336
Security fixes:
337
338
- Fix use-after-free bug in ack_write_buf(), triggerable by a well-timed
339
sequence of control channel + authentication packets ([CVE-2026-12996](https://www.cve.org/CVERecord?id=CVE-2026-12996))
340
341
Bug found by multiple researchers:
342
- 章鱼哥 (www.aipyaipy.com)
343
- Haiyang Huang
344
- Haruki Oyama (Waseda University)
345
346
- Fix use-after-free bug in tls_wrap_reneg(), triggerable by suitable
347
sequence of dynamic tls-crypt control-channel packets ([CVE-2026-13117](https://www.cve.org/CVERecord?id=CVE-2026-13117))
348
349
Bug found by multiple researchers:
350
- Trace37 Labs (github.com/trace37labs)
351
- Haiyang Huang
352
353
- Fix server crash on reception of suitably malformed auth-token, if
354
`--auth-gen-token external-auth` is active ([CVE-2026-13122](https://www.cve.org/CVERecord?id=CVE-2026-13122))
355
356
Bug found by Haiyang Huang.
357
358
- Fix memory-leak in tls-crypt-v2 client key handling that could lead
359
to out-of-memory situations and subsequent server crashes ([CVE-2026-12932](https://www.cve.org/CVERecord?id=CVE-2026-12932))
360
361
Bug found by Valton Tahiri.
362
363
- Fix possible 1-byte buffer overrun on NTLMv2 proxy responses.
364
([CVE-2026-11771](https://www.cve.org/CVERecord?id=CVE-2026-11771))
365
366
Bug found by Tristan Madani (@TristanInSec).
367
368
- Fix another memory leak on reception of suitable tls-crypt-v2 packets
369
that could lead to an out of memory situation and server crash
370
([CVE-2026-13698](https://www.cve.org/CVERecord?id=CVE-2026-13698))
371
372
Bug found by Max Fillinger. Overlaps with a report
373
from Valton Tahiri that we believe to
374
be fixed by this bugfix as well.
375
1be8a9 flichtenheld 2026-07-01 14:43:50 376
Bugfixes:
377
1353e7 flichtenheld 2026-07-01 14:43:01 378
- Windows: fix plugin trusted-dir check prefix bypass
379
(this fixes a bug in the path checking logic we do on Windows for
380
"is loading a plugin from this path allowed?", but since we could
381
not find a way to exploit this unless starting with admin privs or
382
a social engineering attack, not classified as a security fix)
383
384
- options: fix use-after-free of DNS options on client connect
385
(using suitable `--dns` or `--dhcp-option DNS` options in a server
386
config - not pushed, but applying to the server itself - triggers a
387
double free() and use-after-free condition, possibly crashing the
388
server) (Github: [OpenVPN/openvpn#1060](https://github.com/OpenVPN/openvpn/issues/1060))
389
390
- Null-terminate tls-crypt client keys when testing - non-exploitable
391
strlen() on a buffer that is not null-terminated
392
393
- Ensure pushed tun-mtu is no lower than TUN_MTU_MIN - this fixes a bug
394
where a server can push a suitable combination of options and make the
395
client ASSERT().
396
397
(Reported as security issue by Haiyang Huang,
398
but it was decided that the server always has means to make the client
399
"not function properly", and it can not be exploited beyond that)
400
401
Windows MSI changes since 2.6.20-I001:
402
* Built against OpenSSL 3.6.3
403
404
| | | |
405
|-|-|-|
406
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.21-I001-amd64.msi.asc)|[OpenVPN-2.6.21-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.21-I001-amd64.msi)|
407
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.21-I001-arm64.msi.asc)|[OpenVPN-2.6.21-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.21-I001-arm64.msi)|
05fd00 flichtenheld 2026-08-05 19:38:48 408
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.21-I001-x86.msi.asc)|[OpenVPN-2.6.21-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.21-I001-x86.msi)|
1353e7 flichtenheld 2026-07-01 14:43:01 409
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.21.tar.gz.asc)|[openvpn-2.6.21.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.21.tar.gz)|
410
411
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
412
c6c36a flichtenheld 2026-07-01 13:49:39 413
## OpenVPN 2.7.5 -- Released 1 July 2026
414
The OpenVPN community project team is proud to release OpenVPN 2.7.5. This is a bugfix release fixing
415
several security issues.
416
417
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7.5/Changes.rst)
418
419
Security fixes:
420
421
- openvpnserv (windows): fix DNS SearchList state pollution on (dis)connect.
422
specific combinations of `--dns` config entries plus local DNS config
423
could lead to corruption of pre-openvpn DNS config ([CVE-2026-13379](https://www.cve.org/CVERecord?id=CVE-2026-13379))
424
425
Bug found by 章鱼哥 (www.aipyaipy.com).
426
427
- Fix use-after-free bug in ack_write_buf(), triggerable by a well-timed
428
sequence of control channel + authentication packets ([CVE-2026-12996](https://www.cve.org/CVERecord?id=CVE-2026-12996))
429
430
Bug found by multiple researchers:
431
- 章鱼哥 (www.aipyaipy.com)
432
- Haiyang Huang
433
- Haruki Oyama (Waseda University)
434
435
- Fix use-after-free bug in tls_wrap_reneg(), triggerable by suitable
436
sequence of dynamic tls-crypt control-channel packets ([CVE-2026-13117](https://www.cve.org/CVERecord?id=CVE-2026-13117))
437
438
Bug found by multiple researchers:
439
- Trace37 Labs (github.com/trace37labs)
440
- Haiyang Huang
441
442
- Fix server crash on reception of suitably malformed auth-token, if
443
`--auth-gen-token external-auth` is active ([CVE-2026-13122](https://www.cve.org/CVERecord?id=CVE-2026-13122))
444
445
Bug found by Haiyang Huang.
446
447
- Fix memory-leak in tls-crypt-v2 client key handling that could lead
448
to out-of-memory situations and subsequent server crashes ([CVE-2026-12932](https://www.cve.org/CVERecord?id=CVE-2026-12932))
449
450
Bug found by Valton Tahiri.
451
452
- Fix possible 1-byte buffer overrun on NTLMv2 proxy responses.
453
([CVE-2026-11771](https://www.cve.org/CVERecord?id=CVE-2026-11771))
454
455
Bug found by Tristan Madani (@TristanInSec).
456
457
- Fix another memory leak on reception of suitable tls-crypt-v2 packets
458
that could lead to an out of memory situation and server crash
459
([CVE-2026-13698](https://www.cve.org/CVERecord?id=CVE-2026-13698))
460
461
Bug found by Max Fillinger. Overlaps with a report
462
from Valton Tahiri that we believe to
463
be fixed by this bugfix as well.
464
1be8a9 flichtenheld 2026-07-01 14:43:50 465
Bugfixes:
466
c6c36a flichtenheld 2026-07-01 13:49:39 467
- Windows: fix plugin trusted-dir check prefix bypass
468
(this fixes a bug in the path checking logic we do on Windows for
469
"is loading a plugin from this path allowed?", but since we could
470
not find a way to exploit this unless starting with admin privs or
471
a social engineering attack, not classified as a security fix)
472
473
- Windows: openvpnserv: rework ConvertItfDnsDomains and tests
474
(this fixes a buffer overread that is not exploitable and as such
475
not classified as security fix)
476
477
- options: fix use-after-free of DNS options on client connect
478
(using suitable `--dns` or `--dhcp-option DNS` options in a server
479
config - not pushed, but applying to the server itself - triggers a
480
double free() and use-after-free condition, possibly crashing the
481
server) (Github: [OpenVPN/openvpn#1060](https://github.com/OpenVPN/openvpn/issues/1060))
482
483
- dns: Fix memory leak in dns_server_addr_parse, if too many server
484
addresses are configured (Github: [OpenVPN/openvpn#1055](https://github.com/OpenVPN/openvpn/issues/1055))
485
486
- improve multi-socket event handling further - multiple open UDP sockets
487
with concurrent traffic could lead to inefficient processing, and the
488
old code was also very hard to follow.
489
490
(This was initially triggered by a report from Joshua Rogers using ZeroPath,
491
but turned out to be "just bad code" not a security vulnerability)
492
493
- Null-terminate tls-crypt client keys when testing - non-exploitable
494
strlen() on a buffer that is not null-terminated
495
496
- mudp: send HMAC reset reply synchronously
497
this fixes a bug where multiple incoming tls-crypt-v2 RESET packets
498
on different sockets could end up overwriting each other's control
499
structures, leading to initial handshake packets (HMAC reset reply)
500
being sent to the wrong client IP, or on a non-suitable socket
501
("v4 packet on a v6 socket"). Since the overall flow here is stateless
502
by nature, do not artificially create state by creating elaborate
503
queues, just send-or-drop.
504
505
- fix port-share and multi-socket interaction - port-share needs TCP
506
listeners, but the check was wrong. So "as long as any of the listening
507
sockets is TCP, port-share can be used" (Github: [OpenVPN/openvpn#1027](https://github.com/OpenVPN/openvpn/issues/1027))
508
509
- Ensure pushed tun-mtu is no lower than TUN_MTU_MIN - this fixes a bug
510
where a server can push a suitable combination of options and make the
511
client ASSERT().
512
513
(Reported as security issue by Haiyang Huang,
514
but it was decided that the server always has means to make the client
515
"not function properly", and it can not be exploited beyond that)
516
517
- Windows: socket: assert buffer length before reading prepended sockaddr
518
family - a misbehaviour in the windows DCO driver could trigger an
519
overread in the userland client. No such bug exists, which this was
520
not treated as a security vulnerability
521
1be8a9 flichtenheld 2026-07-01 14:43:50 522
Documentation improvements:
523
c6c36a flichtenheld 2026-07-01 13:49:39 524
- improve documentation for `--float` (Github: [OpenVPN/openvpn#358](https://github.com/OpenVPN/openvpn/issues/358))
525
- add documentation for `--preresolve` (Github: [OpenVPN/openvpn#532](https://github.com/OpenVPN/openvpn/issues/532))
526
- impove documentation around DNS config (Github: [OpenVPN/openvpn#937](https://github.com/OpenVPN/openvpn/issues/937))
527
528
Windows MSI changes since 2.7.4-I002:
529
* Built against OpenSSL 3.6.3
530
531
| | | |
532
|-|-|-|
533
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.5-I001-amd64.msi.asc)|[OpenVPN-2.7.5-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.5-I001-amd64.msi)|
534
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.5-I001-arm64.msi.asc)|[OpenVPN-2.7.5-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.5-I001-arm64.msi)|
535
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.5-I001-x86.msi.asc)|[OpenVPN-2.7.5-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.5-I001-x86.msi)|
536
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7.5.tar.gz.asc)|[openvpn-2.7.5.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7.5.tar.gz)|
537
538
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
539
02ae13 flichtenheld 2026-04-30 20:02:29 540
## OpenVPN 2.7.4 -- Released 30 April 2026
541
The OpenVPN community project team is proud to release OpenVPN 2.7.4. This is a small bugfix release.
542
543
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7.4/Changes.rst)
544
545
Bugfixes:
546
547
- using `--dns server ...` style configs on Windows with win-dco would
548
lead to erroneously enabling "DnsSecValidationRequired : True", possibly
549
breaking VPN DNS resolution. Pushing `--dns server ... dnssec no`
550
can be used as a workaround until clients can be updated.
551
(Github: [openvpn#1024](https://github.com/OpenVPN/openvpn/issues/1024))
552
- correct comments in the `--dns-up-down` platform scripts relating to
553
`dns_server_..._dnssec` values.
554
- fix release-only build of pkcs11-helper vcpkg port, do not try to
555
install files from debug build.
556
- mbedTLS builds will now provide a proper error message if a
557
`tls-group` statement with no valid groups is encountered
558
(used to run into SSL handshake failure later on).
559
- `--enable-strict` and `--enable-strict-options` configure flags have
560
been removed (because they did not actually do anything anymore)
561
1213fa flichtenheld 2026-06-10 16:44:15 562
Note: Windows MSI was updated to I002 on June 10th. Changes in I002:
563
564
* Included dco-win driver updated to 2.8.3
565
* [CVE-2026-11604](https://www.cve.org/CVERecord?id=CVE-2026-11604): An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win
566
allows a remote authenticated peer to trigger a heap-based buffer overflow and kernel memory corruption via a crafted data packet, resulting in a system crash
567
(denial of service).
568
02ae13 flichtenheld 2026-04-30 20:02:29 569
| | | |
570
|-|-|-|
1213fa flichtenheld 2026-06-10 16:44:15 571
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.4-I002-amd64.msi.asc)|[OpenVPN-2.7.4-I002-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.4-I002-amd64.msi)|
572
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.4-I002-arm64.msi.asc)|[OpenVPN-2.7.4-I002-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.4-I002-arm64.msi)|
573
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.4-I002-x86.msi.asc)|[OpenVPN-2.7.4-I002-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.4-I002-x86.msi)|
02ae13 flichtenheld 2026-04-30 20:02:29 574
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7.4.tar.gz.asc)|[openvpn-2.7.4.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7.4.tar.gz)|
575
576
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
577
c15d53 uddr 2026-04-27 15:21:55 578
## OpenVPN 2.7.3 -- Released 27 April 2026
579
The OpenVPN community project team is proud to release OpenVPN 2.7.3. This is a small bugfix release.
580
581
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7.3/Changes.rst)
582
583
Bugfixes:
584
585
* in combination with ``--management-query-passwords``, setups using
586
``--auth-user-pass file`` or inline ``auth-user-pass`` would no longer
587
use the configured passwords and prompt on the management interface
588
instead (OpenVPN GUI would then provide an empty user/password prompt)
589
(Github: [openpvn#1021](https://github.com/OpenVPN/openvpn/issues/1021)).
590
591
| | | |
592
|-|-|-|
593
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.3-I001-amd64.msi.asc)|[OpenVPN-2.7.3-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.3-I001-amd64.msi)|
594
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.3-I001-arm64.msi.asc)|[OpenVPN-2.7.3-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.3-I001-arm64.msi)|
595
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.3-I001-x86.msi.asc)|[OpenVPN-2.7.3-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.3-I001-x86.msi)|
596
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7.3.tar.gz.asc)|[openvpn-2.7.3.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7.3.tar.gz)|
597
598
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
599
dab7ff uddr 2026-04-22 14:57:20 600
## OpenVPN 2.7.2 -- Released 22 April 2026
601
The OpenVPN community project team is proud to release OpenVPN 2.7.2. This is a bugfix release containing security fixes.
602
603
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7.2/Changes.rst)
604
605
Security fixes:
606
607
* [CVE-2026-40215](https://www.cve.org/CVERecord?id=CVE-2026-40215): fix race condition in TLS handshake that could lead to leaking of
608
packet data from a previous handshake under specific circumstances
609
* [CVE-2026-35058](https://www.cve.org/CVERecord?id=CVE-2026-35058): fix server ASSERT() on receiving a suitably malformed packet with
610
a valid tls-crypt-v2 key
611
612
New features:
613
614
* management interface: permit input of very long passwords in
615
base64-encoded multiline format. Signal support to management
616
clients via "management version 6".
617
618
User-visible Changes:
619
620
* improve error messages on ``--verify-x509-name`` failures
621
* improve error logging when overlong username or passwords can not
622
be written to TLS buffer
623
624
Bugfixes:
625
626
* when using a config file with inlined username and no password,
627
fix prompting for the password from management interface.
628
* Windows: fix DNSSEC flag handling - this got never applied due to
629
a bad comparison being always false.
630
* Windows: fix deinstallation progress bar on adapter deletion.
631
632
Windows MSI changes since 2.7.1:
633
* Built against OpenSSL 3.6.2
634
* Included openvpn-gui updated to 11.63.0.0
635
* Translation cleanup. Remove obsolete strings related to support for OpenVPN < 2.0
636
* Translation updates.
637
638
| | | |
639
|-|-|-|
640
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.2-I001-amd64.msi.asc)|[OpenVPN-2.7.2-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.2-I001-amd64.msi)|
641
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.2-I001-arm64.msi.asc)|[OpenVPN-2.7.2-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.2-I001-arm64.msi)|
642
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.2-I001-x86.msi.asc)|[OpenVPN-2.7.2-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.2-I001-x86.msi)|
643
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7.2.tar.gz.asc)|[openvpn-2.7.2.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7.2.tar.gz)|
644
645
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
646
647
## OpenVPN 2.6.20 -- Released 22 April 2026
648
The OpenVPN community project team is proud to release OpenVPN 2.6.20. This is a bugfix release containing security fixes.
649
650
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.20/Changes.rst)
651
652
Security fixes:
653
654
* [CVE-2026-40215](https://www.cve.org/CVERecord?id=CVE-2026-40215): fix race condition in TLS handshake that could lead to leaking of
655
packet data from a previous handshake under specific circumstances
656
* [CVE-2026-35058](https://www.cve.org/CVERecord?id=CVE-2026-35058): fix server ASSERT() on receiving a suitably malformed packet with
657
a valid tls-crypt-v2 key
658
659
Bugfixes:
660
661
* management: stop periodic bytecount output on mgmt client disconnection
662
* FreeBSD: make DCO work on systems with no IPv4 support
663
* FreeBSD: fix compilation with --enable-async-push on FreeBSD 15
664
* Linux: make DCO work on big endian architectures (MIPS, PowerPC)
665
* Windows: fix deinstallation progress bar on adapter deletion.
666
* Linux: fix problem with DCO kernel notifications getting lost, leading
667
to overcounting of number of connected clients and general confusion
668
between kernel and userland regarding peer status (Github [#900](https://github.com/OpenVPN/openvpn/issues/900), [#918](https://github.com/OpenVPN/openvpn/issues/918),
669
[#931](https://github.com/OpenVPN/openvpn/issues/931), [#919](https://github.com/OpenVPN/openvpn/issues/919), [#945](https://github.com/OpenVPN/openvpn/issues/945)) - this is a backport of the fixes in 2.7 plus the
670
infrastructural changes around DCO needed to support it.
671
672
Windows MSI changes since 2.6.19-I001:
673
* Built against OpenSSL 3.6.2
674
* Included openvpn-gui updated to 11.63.0.0
675
* Translation cleanup. Remove obsolete strings related to support for OpenVPN < 2.0
676
* Translation updates.
677
678
| | | |
679
|-|-|-|
680
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.20-I001-amd64.msi.asc)|[OpenVPN-2.6.20-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.20-I001-amd64.msi)|
681
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.20-I001-arm64.msi.asc)|[OpenVPN-2.6.20-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.20-I001-arm64.msi)|
682
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.20-I001-x86.msi.asc)|[OpenVPN-2.6.20-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.20-I001-x86.msi)|
683
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.20.tar.gz.asc)|[openvpn-2.6.20.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.20.tar.gz)|
684
feaea5 uddr 2026-04-22 14:59:21 685
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
686
8ec6a8 flichtenheld 2026-03-31 15:56:48 687
## OpenVPN 2.7.1 -- Released 31 March 2026
688
The OpenVPN community project team is proud to release OpenVPN 2.7.1. This is a bug fix release.
689
690
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7.1/Changes.rst)
691
692
New features:
693
694
- Add a new `username-only` flag argument to `--auth-user-pass` which
695
will now make OpenVPN only query for username and send a dummy password
696
to the server. This is only useful if auth schemes are used on the
697
server side that will do some sort of external challenge base on username,
698
and not password authentication. See discussion in
699
GH [OpenVPN/openvpn#501](https://github.com/OpenVPN/openvpn/issues/501)
700
(starting Jan 30, 2024).
701
- Increase default sizing of internal hash maps to `4 * --max-clients`.
702
The default used to be `256` with a `--max-clients` default of
703
1024 - this is bad for performance, while the memory savings are
704
minimal. On a very memory constrained system, reduce `--max-clients`.
705
706
User-visible Changes:
707
708
- When compiled with the AWS-LC SSL library, using `--tls-cert-profile`
709
will now print a run-time warning - the library does not support it,
710
so it would silently do nothing.
711
- Systemd unit files: change LimitNPROC to TasksMax and increase limit
712
(GH: [OpenVPN/openvpn#929](https://github.com/OpenVPN/openvpn/issues/929))
713
- Documentation improvements.
714
- port-share: log incoming connections at `verb 3`, not on `error`
715
level anymore (GH: [OpenVPN/openvpn#976](https://github.com/OpenVPN/openvpn/issues/976)).
716
717
Bugfixes:
718
719
- Fix usage of `--lport` inside a `<connection>` block - this got
720
broken with the multi-socket patchset (GH: [OpenVPN/openvpn#995](https://github.com/OpenVPN/openvpn/issues/995))
721
- Do not try to run auto-pam unit test when cross-compiling.
722
- Do not break private-key passphrases of length >= 64
723
(GH: [OpenVPN/openvpn#993](https://github.com/OpenVPN/openvpn/issues/993))
724
- Fix obscure ASSERT() crash on TCP connects with TAP and no ip config.
725
- Make DCO work on FreeBSD systems that have no IPv4 support in kernel
726
(FreeBSD PR 286263)
727
- Make DCO work on Linux on big endian systems (namely, MIPS and PowerPC)
728
(GH: [OpenVPN/ovpn-dco#96](https://github.com/OpenVPN/ovpn-dco/issues/96))
729
- Fixup responses to management interface ``version`` command (for >= 4)
730
- Make `--enable-async-push` work on FreeBSD 15 (which has native
731
inotify support, and consequently no libinotify.pc anymore)
732
- Adjust some code parts to new "const" handling on string function
733
returns (ISO C23, as implemented by glibc 2.43 and newer).
734
735
Windows MSI changes since 2.7.1:
736
* Make sure that included openvpnserv2.exe is signed (GH: [OpenVPN/openvpn-build#1293](https://github.com/OpenVPN/openvpn-build/issues/1293))
737
* Included openvpn-gui updated to 11.62.0.0
738
* Translation updates
739
740
| | | |
741
|-|-|-|
742
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.1-I001-amd64.msi.asc)|[OpenVPN-2.7.1-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.1-I001-amd64.msi)|
743
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.1-I001-arm64.msi.asc)|[OpenVPN-2.7.1-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.1-I001-arm64.msi)|
744
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.1-I001-x86.msi.asc)|[OpenVPN-2.7.1-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.1-I001-x86.msi)|
745
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7.1.tar.gz.asc)|[openvpn-2.7.1.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7.1.tar.gz)|
746
747
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
748
586cd5 flichtenheld 2026-02-11 12:56:28 749
## OpenVPN 2.7.0 -- Released 11 February 2026
750
The OpenVPN community project team is proud to release OpenVPN 2.7.0.
751
This is the new stable version of OpenVPN with some major new features.
752
753
This release has only minor changes relative to the last release candidate release 2.7_rc6.
754
For a list of these changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_rc6...v2.7.0).
755
756
Highlights of 2.7 include:
757
* Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
758
* Improved Client support for DNS options
759
* Client implementations for Linux/BSD/macOS, included with the default install
760
* New client implementation for Windows, adding support for features like split DNS and DNSSEC
761
* Architectural improvements on Windows
762
* The `block-local` flag is now enforced with WFP filters
763
* Windows network adapters are now generated on demand
764
* Windows automatic service now runs as an unpriviledged user
765
* Support for server mode in win-dco driver
766
* Note: Support for the wintun driver has been removed. win-dco is now the default, tap-windows6 is the fallback solution for use-cases not covered by win-dco.
767
* Improved data channel
768
* Enforcement of AES-GCM usage limit
769
* Epoch data keys and packet format
770
* Support for new upstream DCO Linux kernel module
771
* This release supports the new `ovpn` DCO Linux kernel module which will be available in future upstream Linux kernel releases. Backports of the new module to current kernels are available via the [ovpn-backports project](https://github.com/OpenVPN/ovpn-backports).
772
* Client-side support for new `PUSH_UPDATE` control-channel message
773
* This allows servers to send updates to options like routing and DNS config without triggering a reconnect.
774
* PUSH_UPDATE server support (minimal)
775
* New management interface commands `push-update-broad` and `push-update-cid` to send PUSH_UPDATE option updates.
776
* TLS 1.3 support with bleeding-edge mbedTLS versions
777
* Support for mbedTLS version 4
778
* Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
779
* Support for Epoch data channel on Windows, using the win-dco driver (2.8.0+)
780
* "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
781
* COPYING: license details only relevant to our Windows installers have been updated and moved to the openvpn-build repo
782
783
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7.0/Changes.rst)
784
f35e01 uddr 2026-02-19 13:08:59 785
Note: Windows MSI was updated to I017 on February 19th. Changes in I017:
786
* msi: use Wix Util:EventSource to register OpenVPNService event source instead of PowerShell. GH: [openvpn-build #1230](https://github.com/OpenVPN/openvpn-build/issues/1230)
787
* Included dco-win driver updated to 2.8.2
788
* [CVE-2026-2738](https://www.cve.org/CVERecord?id=CVE-2026-2738): Fix TX buffer overflow in epoch AEAD encryption. GH: [ovpn-dco-win #130](https://github.com/OpenVPN/ovpn-dco-win/issues/130)
789
586cd5 flichtenheld 2026-02-11 12:56:28 790
| | | |
791
|-|-|-|
f35e01 uddr 2026-02-19 13:08:59 792
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.0-I017-amd64.msi.asc)|[OpenVPN-2.7.0-I017-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.0-I017-amd64.msi)|
793
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.0-I017-arm64.msi.asc)|[OpenVPN-2.7.0-I017-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.0-I017-arm64.msi)|
794
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.0-I017-x86.msi.asc)|[OpenVPN-2.7.0-I017-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.0-I017-x86.msi)|
586cd5 flichtenheld 2026-02-11 12:56:28 795
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7.0.tar.gz.asc)|[openvpn-2.7.0.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7.0.tar.gz)|
796
797
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
798
8416a7 flichtenheld 2026-02-04 18:04:59 799
## OpenVPN 2.6.19 -- Released 4 February 2026
800
The OpenVPN community project team is proud to release OpenVPN 2.6.19. This is a bugfix release.
801
2.6.19 only fixes one small issue in the creation of the 2.6.18 release tarball. It was released
802
on the same day as 2.6.18.
803
804
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.19/Changes.rst)
805
806
Bugfixes:
807
* `make dist` would fail to pack `unit_tests/openvpn/test_common.h`,
808
breaking `make check` on the tarball if cmocka is installed. Fix.
809
810
| | | |
811
|-|-|-|
812
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.19-I001-amd64.msi.asc)|[OpenVPN-2.6.19-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.19-I001-amd64.msi)|
813
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.19-I001-arm64.msi.asc)|[OpenVPN-2.6.19-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.19-I001-arm64.msi)|
814
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.19-I001-x86.msi.asc)|[OpenVPN-2.6.19-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.19-I001-x86.msi)|
815
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.19.tar.gz.asc)|[openvpn-2.6.19.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.19.tar.gz)|
816
817
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
818
fbee78 flichtenheld 2026-02-04 14:23:26 819
## OpenVPN 2.6.18 -- Released 4 February 2026
820
The OpenVPN community project team is proud to release OpenVPN 2.6.18. This is a bugfix release.
821
822
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.18/Changes.rst)
823
824
User visible changes:
825
* disable DCO if `--bind-dev` option is given (no support for this in
826
the old out-of-kernel Linux DCO implementation)
827
* on Windows, if using `--ip-win32 netsh` and not using the interactive
828
service, IPv4 addresses would be installed as "permanent", possibly
829
causing problems later on with using that IPv4 address on a different
830
interface. Change to "store=active". (GH: [#915](https://github.com/OpenVPN/openvpn/issues/915))
831
* improve pull-filter documentation, emphasizing possible problems if
832
used as a naive security measure (reported by SRLabs)
833
834
Bugfixes:
835
* p2mp server: fix incorrect file descriptor handling on "inotify" FD
836
during a SIGUSR1 restart (GH: [#966](https://github.com/OpenVPN/openvpn/issues/966))
837
* management interface: fix bug where `--management-forget-disconnect`
838
and `--management-signal` could be executed even if password authentication
839
to managment interface was still pending (ZeroPath finding)
840
* repair client-side interaction on reconnect between DCO event handling
841
and `--persist-tun` - after a ping timeout and reconnect, the DCO
842
event handler would not be armed, and the next ping timeout would not
843
be received by userland, causing non-working connections with nothing
844
in the openvpn log (Linux and FreeBSD only, GH: [#947](https://github.com/OpenVPN/openvpn/issues/947))
845
- prevent crash on invalid server-ipv6 argument, calling `freeaddrinfo()`
846
with a NULL pointer. This only affects OpenBSD. (Klemens Nanni).
847
848
Windows MSI changes since 2.6.17-I001:
849
* Built against OpenSSL 3.6.1
850
* Included openvpn-gui updated to 11.61.0.0
851
* translation updates
852
853
| | | |
854
|-|-|-|
855
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.18-I001-amd64.msi.asc)|[OpenVPN-2.6.18-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.18-I001-amd64.msi)|
856
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.18-I001-arm64.msi.asc)|[OpenVPN-2.6.18-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.18-I001-arm64.msi)|
857
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.18-I001-x86.msi.asc)|[OpenVPN-2.6.18-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.18-I001-x86.msi)|
858
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.18.tar.gz.asc)|[openvpn-2.6.18.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.18.tar.gz)|
859
860
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
861
1b7e87 flichtenheld 2026-01-28 16:33:47 862
## OpenVPN 2.7_rc6 -- Released 28 January 2026
863
The OpenVPN community project team is proud to release OpenVPN 2.7_rc6. This is the sixth release candidate for the feature release 2.7.0.
864
865
Important changes since 2.7_rc5:
866
* bugfix on restarting a p2mp server instance with SIGUSR1 (inadvertedly
867
closing fd 0, causing a crash on the next restart - GH [OpenVPN/openvpn#966](https://github.com/OpenVPN/openvpn/issues/966))
868
* prevent NULL pointer crash on suitable combination of --dns-updown
869
statements in openvpn config file (not pushable)
870
* prevent inappropriate management interface activity if a password is
871
set and --management-forget-disconnect or --management-signal are active
872
* add mbedTLS 4 support
873
874
For a list of all changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_rc5...v2.7_rc6).
875
876
Highlights of 2.7 include:
877
* Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
878
* Improved Client support for DNS options
879
* Client implementations for Linux/BSD/macOS, included with the default install
880
* New client implementation for Windows, adding support for features like split DNS and DNSSEC
881
* Architectural improvements on Windows
882
* The `block-local` flag is now enforced with WFP filters
883
* Windows network adapters are now generated on demand
884
* Windows automatic service now runs as an unpriviledged user
885
* Support for server mode in win-dco driver
886
* Note: Support for the wintun driver has been removed. win-dco is now the default, tap-windows6 is the fallback solution for use-cases not covered by win-dco.
887
* Improved data channel
888
* Enforcement of AES-GCM usage limit
889
* Epoch data keys and packet format
890
* Support for new upstream DCO Linux kernel module
891
* This release supports the new `ovpn` DCO Linux kernel module which will be available in future upstream Linux kernel releases. Backports of the new module to current kernels are available via the [ovpn-backports project](https://github.com/OpenVPN/ovpn-backports).
892
* Client-side support for new `PUSH_UPDATE` control-channel message
893
* This allows servers to send updates to options like routing and DNS config without triggering a reconnect.
894
* PUSH_UPDATE server support (minimal)
895
* New management interface commands `push-update-broad` and `push-update-cid` to send PUSH_UPDATE option updates.
896
* TLS 1.3 support with bleeding-edge mbedTLS versions
897
* Support for mbedTLS version 4
898
* Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
899
* Support for Epoch data channel on Windows, using the win-dco driver (2.8.0+)
900
* "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
901
* COPYING: license details only relevant to our Windows installers have been updated and moved to the openvpn-build repo
902
903
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_rc6/Changes.rst)
904
7281a5 flichtenheld 2026-02-04 16:00:45 905
Windows MSI was updated on Feb 4th to 2.7_rc6-I015 to rebuild with updated OpenSSL 3.6.1.
906
1b7e87 flichtenheld 2026-01-28 16:33:47 907
| | | |
908
|-|-|-|
909
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc6-I014-amd64.msi.asc)|[OpenVPN-2.7_rc6-I014-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc6-I014-amd64.msi)|
910
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc6-I014-arm64.msi.asc)|[OpenVPN-2.7_rc6-I014-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc6-I014-arm64.msi)|
911
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc6-I014-x86.msi.asc)|[OpenVPN-2.7_rc6-I014-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc6-I014-x86.msi)|
912
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc6.tar.gz.asc)|[openvpn-2.7_rc6.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc6.tar.gz)|
913
914
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
915
a0aa83 uddr 2026-01-15 18:06:38 916
## OpenVPN 2.7_rc5 -- Released 15 January 2026
917
The OpenVPN community project team is proud to release OpenVPN 2.7_rc5. This is the fifth release candidate for the feature release 2.7.0.
918
919
Security fixes:
920
* [CVE-2025-15497](https://www.cve.org/CVERecord?id=CVE-2025-15497): in epoch key handling (an authenticated remote system
921
can send a valid OpenVPN data packet that triggers an edge case
922
where a too-strict check would trigger an ASSERT(), exiting OpenVPN)
923
924
Important bug fixes since 2.7_rc4:
925
* remove "resolve --remote on incoming TCP connects on --tcp-server"
926
code base, because that did not work in a long time (since 2.4) and
927
is seen as too obscure and too complicated to rescue.
928
* repair interaction between DCO and persist-tun after reconnection
929
(in this case the client side would fail to set up the DCO event
930
handler, and not notice further --ping timeouts - GH: #947)
931
* remove ENABLE_X509ALTUSERNAME conditional, always enabling
932
"configure --enable-x509-alt-username". Effectively no change in
933
code size, and one less build variant to maintain and test (GH: [OpenVPN/openvpn#917](https://github.com/OpenVPN/openvpn/issues/917)).
934
* require "script-security 2" when using `--dev unix:<program>`
935
* socks client: fix and improve various code parts
936
* configure etc: drop support for systemd 216 and older, adapt
937
other checks to reflect modern systemd setups
938
* fix unit test building with libcmocka 2.0+
939
* fix Android build warnings about unused variables/methods
940
* allow --test-crypto to run without --secret
941
(prepare for removal of --secret after 2.7)
942
* improve WolfSSL build compatibility
943
944
For a list of all changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_rc4...v2.7_rc5).
945
946
Highlights of 2.7 include:
947
* Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
948
* Improved Client support for DNS options
949
* Client implementations for Linux/BSD/macOS, included with the default install
950
* New client implementation for Windows, adding support for features like split DNS and DNSSEC
951
* Architectural improvements on Windows
952
* The `block-local` flag is now enforced with WFP filters
953
* Windows network adapters are now generated on demand
954
* Windows automatic service now runs as an unpriviledged user
955
* Support for server mode in win-dco driver
956
* Note: Support for the wintun driver has been removed. win-dco is now the default, tap-windows6 is the fallback solution for use-cases not covered by win-dco.
957
* Improved data channel
958
* Enforcement of AES-GCM usage limit
959
* Epoch data keys and packet format
960
* Support for new upstream DCO Linux kernel module
961
* This release supports the new `ovpn` DCO Linux kernel module which will be available in future upstream Linux kernel releases. Backports of the new module to current kernels are available via the [ovpn-backports project](https://github.com/OpenVPN/ovpn-backports).
962
* Client-side support for new `PUSH_UPDATE` control-channel message
963
* This allows servers to send updates to options like routing and DNS config without triggering a reconnect.
964
* PUSH_UPDATE server support (minimal)
965
* New management interface commands `push-update-broad` and `push-update-cid` to send PUSH_UPDATE option updates.
966
* TLS 1.3 support with bleeding-edge mbedTLS versions
967
* Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
968
* Support for Epoch data channel on Windows, using the win-dco driver (2.8.0+)
969
* "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
970
* COPYING: license details only relevant to our Windows installers have been updated and moved to the openvpn-build repo
971
972
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_rc5/Changes.rst)
973
974
Windows MSI changes since 2.7_rc4:
975
* Built against OpenSSL 3.6.0
976
* Included openvpn-gui updated to 11.61.0.0
977
* Included win-dco driver updated to 2.8.0
978
979
| | | |
980
|-|-|-|
981
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc5-I013-amd64.msi.asc)|[OpenVPN-2.7_rc5-I013-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc5-I013-amd64.msi)|
982
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc5-I013-arm64.msi.asc)|[OpenVPN-2.7_rc5-I013-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc5-I013-arm64.msi)|
983
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc5-I013-x86.msi.asc)|[OpenVPN-2.7_rc5-I013-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc5-I013-x86.msi)|
984
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc5.tar.gz.asc)|[openvpn-2.7_rc5.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc5.tar.gz)|
985
986
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
987
257cb5 uddr 2025-12-17 19:05:32 988
## OpenVPN 2.7_rc4 -- Released 17 December 2025
989
The OpenVPN community project team is proud to release OpenVPN 2.7_rc4. This is the fourth release candidate for the feature release 2.7.0.
990
991
Important bug fixes since 2.7_rc3:
992
* Windows interactive service: do not configure adapter DNS if
993
there are no search-domains but there are resolve-domains (which
994
get resolved via NRPT rules) - GH: [OpenVPN/openvpn#473](https://github.com/OpenVPN/openvpn/issues/473)
995
* improve documentation and error messages for a number of deprecated
996
options
997
* improve documentation for not-really-deprecated-yet ``--ns-cert-type``
998
* Windows IPv4 configuration with netsh.exe: ensure addresses are added
999
with "store=active" (ensure proper cleanup) - GH: [OpenVPN/openvpn#915](https://github.com/OpenVPN/openvpn/issues/915)
1000
* Windows: set UTF8 code page in openvpn.exe manifest, to make cert/key
1001
loading work again for files with non-ASCII characters in their file
1002
name (GH: [OpenVPN/openvpn#920](https://github.com/OpenVPN/openvpn/issues/920))
1003
* tun.c: unify read_tun()/write_tun() functions for all BSD platforms
1004
* more type conversion related cleanups
1005
* add NULL check before freeaddrinfo() call, which might lead to a
1006
crash on OpenBSD (GH: [OpenVPN/openvpn#930](https://github.com/OpenVPN/openvpn/issues/930))
1007
* add NULL check to mbedtls handling of external and inline certificates
1008
* add check for auth none / cipher none on FreeBSD DCO
1009
* add CAP_SYS_NICE to positive list in Linux systemd unit files
1010
(GH: [OpenVPN/openvpn#834](https://github.com/OpenVPN/openvpn/issues/834))
1011
* drop mbedtls 2.x support (which is end of life, and work on mbedtls 4
1012
is much simplified by not having to take care of 2.x compat as well)
1013
* PUSH_UPDATE: bugfix for the client side where split/continued messages
1014
(due to large number of "route" statements) would not correctly handle
1015
the full set of routes. Add unit test. (GH: [OpenVPN/openvpn#925](https://github.com/OpenVPN/openvpn/issues/925))
1016
* new unit test module for mbuf handling
1017
* deprecate --fast-io option (it got partially broken by the multisocket
1018
implementation, and the benefits of the existing implementation did
1019
not outweigh the extra code complexity to make it work again)
1020
* change the ssl_ctx in struct tls_options to be a pointer - this is
1021
a shared data structure between various contexts, but previously it
1022
was shallow-copied, leading to needless CRL reloading - and when
1023
working on implementing the new OpenSSL CRL API, to segfaults
1024
(the existing code works, as these new APIs are not used yet).
1025
1026
For a list of all changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_rc3...v2.7_rc4).
1027
1028
Highlights of 2.7 include:
1029
* Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
1030
* Improved Client support for DNS options
1031
* Client implementations for Linux/BSD/macOS, included with the default install
1032
* New client implementation for Windows, adding support for features like split DNS and DNSSEC
1033
* Architectural improvements on Windows
1034
* The `block-local` flag is now enforced with WFP filters
1035
* Windows network adapters are now generated on demand
1036
* Windows automatic service now runs as an unpriviledged user
1037
* Support for server mode in win-dco driver
1038
* Note: Support for the wintun driver has been removed. win-dco is now the default, tap-windows6 is the fallback solution for use-cases not covered by win-dco.
1039
* Improved data channel
1040
* Enforcement of AES-GCM usage limit
1041
* Epoch data keys and packet format
1042
* Support for new upstream DCO Linux kernel module
1043
* This release supports the new `ovpn` DCO Linux kernel module which will be available in future upstream Linux kernel releases. Backports of the new module to current kernels are available via the [ovpn-backports project](https://github.com/OpenVPN/ovpn-backports).
1044
* Client-side support for new `PUSH_UPDATE` control-channel message
1045
* This allows servers to send updates to options like routing and DNS config without triggering a reconnect.
1046
* PUSH_UPDATE server support (minimal)
1047
* New management interface commands `push-update-broad` and `push-update-cid` to send PUSH_UPDATE option updates.
1048
* TLS 1.3 support with bleeding-edge mbedTLS versions
1049
* Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
1050
* Support for Epoch data channel on Windows, using the win-dco driver (2.8.0+)
1051
* "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
1052
* COPYING: license details only relevant to our Windows installers have been updated and moved to the openvpn-build repo
1053
1054
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_rc4/Changes.rst)
1055
1056
Windows MSI changes since 2.7_rc3:
1057
* Built against OpenSSL 3.6.0
1058
* Included openvpn-gui updated to 11.60.0.0
1059
* Update copyright year in About dialog
1060
* Included win-dco driver updated to 2.8.0
1061
1062
| | | |
1063
|-|-|-|
1064
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc4-I012-amd64.msi.asc)|[OpenVPN-2.7_rc4-I012-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc4-I012-amd64.msi)|
1065
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc4-I012-arm64.msi.asc)|[OpenVPN-2.7_rc4-I012-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc4-I012-arm64.msi)|
1066
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc4-I012-x86.msi.asc)|[OpenVPN-2.7_rc4-I012-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc4-I012-x86.msi)|
1067
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc4.tar.gz.asc)|[openvpn-2.7_rc4.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc4.tar.gz)|
1068
1069
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
1070
28d111 uddr 2025-11-28 18:07:25 1071
## OpenVPN 2.7_rc3 -- Released 28 November 2025
1072
The OpenVPN community project team is proud to release OpenVPN 2.7_rc3. This is the third release candidate for the feature release 2.7.0.
1073
1074
Security fixes:
1075
* [CVE-2025-13751](https://www.cve.org/CVERecord?id=CVE-2025-13751): Windows/interactive service: fix bug where the interactive service would error-exit in
1076
certain error conditions instead of just logging the fact and
1077
continuing. After the error-exit, OpenVPN connections will no
1078
longer work until the service is restarted (or the system rebooted).
1079
This can be triggered by any authenticated local user, and has
1080
thus been classified as a "local denial of service" attack.
1081
1082
Important bug fixes since 2.7_rc2:
1083
* Windows/Interactive Service bugfixes:
1084
many small bugfixes to registry-related DNS domain handling
1085
* Windows/Interactive Service: harden service pipe handling
1086
close a small race condition, and add restrictive ACLs
1087
* more type conversion related warnings have been fixed
1088
* --multihome behaviour regarding egress interface selection has been
1089
changed. See Changes.rst and manpage for details.
1090
* cleanup dead code in event handling code (leftover of the multisocket
1091
patch set)
1092
* add new feature, --tls-crypt-v2-max-age n. See Changes.rst and
1093
manpage for details.
1094
* improve documentation to point out the pitfalls of case-insensitive
1095
filesystems and --client-config-dir
1096
* split default gateway query logic in two:
1097
* for --redirect-gateway functionality, query for the gateway towards
1098
the actual IP address of the VPN server connecting to
1099
* for the "net_gateway" special destination for --route, and the
1100
corresponding environment variable, always query for 0.0.0.0 / ::
1101
(this will only make a difference in certain scenarios using a local
1102
proxy, or on a system with multiple interfaces, not using the "default
1103
route" for the VPN connection * see github#890)
1104
* upgrade embedded pkcs11-helper vcpkg + pkcs11-uri patch to 1.31
1105
* CMake / autoconf cleanup wrt unused checks, outdated old-Linux checks,
1106
Windows oddities
1107
* DCO (primarily Linux): improve handling of bulk notifications from
1108
kernel (do not lose notifications, do not crash) ([github#900](https://github.com/OpenVPN/openvpn/issues/900))
1109
1110
For a list of all changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_rc2...v2.7_rc3).
1111
1112
Highlights of 2.7 include:
1113
* Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
1114
* Improved Client support for DNS options
1115
* Client implementations for Linux/BSD/macOS, included with the default install
1116
* New client implementation for Windows, adding support for features like split DNS and DNSSEC
1117
* Architectural improvements on Windows
1118
* The `block-local` flag is now enforced with WFP filters
1119
* Windows network adapters are now generated on demand
1120
* Windows automatic service now runs as an unpriviledged user
1121
* Support for server mode in win-dco driver
1122
* Note: Support for the wintun driver has been removed. win-dco is now the default, tap-windows6 is the fallback solution for use-cases not covered by win-dco.
1123
* Improved data channel
1124
* Enforcement of AES-GCM usage limit
1125
* Epoch data keys and packet format
1126
* Support for new upstream DCO Linux kernel module
1127
* This release supports the new `ovpn` DCO Linux kernel module which will be available in future upstream Linux kernel releases. Backports of the new module to current kernels are available via the [ovpn-backports project](https://github.com/OpenVPN/ovpn-backports).
1128
* Client-side support for new `PUSH_UPDATE` control-channel message
1129
* This allows servers to send updates to options like routing and DNS config without triggering a reconnect.
1130
* PUSH_UPDATE server support (minimal)
1131
* New management interface commands `push-update-broad` and `push-update-cid` to send PUSH_UPDATE option updates.
1132
* TLS 1.3 support with bleeding-edge mbedTLS versions
1133
* Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
1134
* Support for Epoch data channel on Windows, using the win-dco driver (2.8.0+)
1135
* "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
1136
* COPYING: license details only relevant to our Windows installers have been updated and moved to the openvpn-build repo
1137
1138
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_rc3/Changes.rst)
1139
1140
Windows MSI changes since 2.7_rc2:
1141
* Built against OpenSSL 3.6.0
1142
* Included openvpn-gui updated to 11.59.0.0
1143
* Authorize config before opening the service pipe
1144
* Remove dependence on pathcch.dll not in Windows 7
1145
* Included win-dco driver updated to 2.8.0
1146
1147
| | | |
1148
|-|-|-|
1149
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc3-I010-amd64.msi.asc)|[OpenVPN-2.7_rc3-I010-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc3-I010-amd64.msi)|
1150
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc3-I010-arm64.msi.asc)|[OpenVPN-2.7_rc3-I010-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc3-I010-arm64.msi)|
1151
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc3-I010-x86.msi.asc)|[OpenVPN-2.7_rc3-I010-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc3-I010-x86.msi)|
1152
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc3.tar.gz.asc)|[openvpn-2.7_rc3.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc3.tar.gz)|
1153
1154
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
1155
1156
## OpenVPN 2.6.17 -- Released 28 November 2025
1157
The OpenVPN community project team is proud to release OpenVPN 2.6.17. This is a bugfix release containing one security fix.
1158
1159
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.17/Changes.rst)
1160
1161
Security fixes:
1162
1163
* [CVE-2025-13751](https://www.cve.org/CVERecord?id=CVE-2025-13751): Windows/interactive service: fix erroneous exit on error that could be
1164
used by a local Windows users to achieve a local denial-of-service
1165
1166
Bug fixes:
1167
1168
* Windows/interactive service: improve service pipe robustness against
1169
file access races (uuid) and access by unauthorized processes (ACL).
1170
* upgrade bundled build instruction (vcpkg and patch) for pkcs11-helper
1171
to 1.31, fixing a parser bug
1172
1173
Windows MSI changes since 2.6.16-I001:
1174
* Built against OpenSSL 3.6.0
1175
* Included openvpn-gui updated to 11.59.0.0
1176
* Authorize config before opening the service pipe
1177
* Remove dependence on pathcch.dll not in Windows 7
1178
* Included win-dco driver updated to 2.8.0
1179
1180
| | | |
1181
|-|-|-|
1182
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.17-I001-amd64.msi.asc)|[OpenVPN-2.6.17-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.17-I001-amd64.msi)|
1183
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.17-I001-arm64.msi.asc)|[OpenVPN-2.6.17-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.17-I001-arm64.msi)|
1184
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.17-I001-x86.msi.asc)|[OpenVPN-2.6.17-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.17-I001-x86.msi)|
1185
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.17.tar.gz.asc)|[openvpn-2.6.17.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.17.tar.gz)|
1186
1187
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
1188
4293c2 uddr 2025-11-17 18:01:55 1189
## OpenVPN 2.7_rc2 -- Released 17 November 2025
1190
The OpenVPN community project team is proud to release OpenVPN 2.7_rc2. This is the second release candidate for the feature release 2.7.0.
1191
1192
Security fixes:
1193
* [CVE-2025-12106](https://www.cve.org/CVERecord?id=CVE-2025-12106): IPv6 address parsing: fix buffer overread on invalid input
1194
* [CVE-2025-13086](https://www.cve.org/CVERecord?id=CVE-2025-13086): HMAC verification check: fix incorrect memcmp() call
1195
1196
Important bug fixes since 2.7_rc1:
1197
* even more type conversion related warnings have been fixed
1198
* DCO FreeBSD improvements:
1199
* improving debug messages (verb 6)
1200
* implement client-side counter handling
1201
* repair --inactive (and document shortcomings)
1202
* repair handling of DCO disconnection notifications in --client mode
1203
* Windows/Service improvements, hardening, bugfixes
1204
* fix DNS address list generation (if 3 or more --dns addresses in use)
1205
* fix DNS server undo_list
1206
* disallow "stdin" as config name unless user has OpenVPN admin privs
1207
* fix compilation errors with MSVC v19
1208
* iservice: improve validation of config path (pathcc lib)
1209
* [NOTE: this breaks OpenVPN compatibility with Windows 7]
1210
* tapctl: refactor, improve output, change driver default to ovpn-dco
1211
* iservice: when restoring iface metrics, enforce correct ifindex
1212
* improve cmocka unit test assert() handling
1213
* PUSH_UPDATE server: fix reporting of client IPs in ``status`` output after pushing a new IPv4/IPv6 address to client
1214
* AEAD cipher safety margins: fix calculation of AEAD blocks in use (old code would undercount blocks)
1215
* fix invalid pointer creation / memory overread in tls_pre_decrypt
1216
* deprecate ``--opt-verify`` (change into no-op + warning)
1217
1218
For a list of all changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_rc1...v2.7_rc2).
1219
1220
Highlights of 2.7 include:
1221
* Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
1222
* Improved Client support for DNS options
1223
* Client implementations for Linux/BSD/macOS, included with the default install
1224
* New client implementation for Windows, adding support for features like split DNS and DNSSEC
1225
* Architectural improvements on Windows
1226
* The `block-local` flag is now enforced with WFP filters
1227
* Windows network adapters are now generated on demand
1228
* Windows automatic service now runs as an unpriviledged user
1229
* Support for server mode in win-dco driver
1230
* Note: Support for the wintun driver has been removed. win-dco is now the default, tap-windows6 is the fallback solution for use-cases not covered by win-dco.
1231
* Improved data channel
1232
* Enforcement of AES-GCM usage limit
1233
* Epoch data keys and packet format
1234
* Support for new upstream DCO Linux kernel module
1235
* This release supports the new `ovpn` DCO Linux kernel module which will be available in future upstream Linux kernel releases. Backports of the new module to current kernels are available via the [ovpn-backports project](https://github.com/OpenVPN/ovpn-backports).
1236
* Client-side support for new `PUSH_UPDATE` control-channel message
1237
* This allows servers to send updates to options like routing and DNS config without triggering a reconnect.
1238
* PUSH_UPDATE server support (minimal)
1239
* New management interface commands `push-update-broad` and `push-update-cid` to send PUSH_UPDATE option updates.
1240
* TLS 1.3 support with bleeding-edge mbedTLS versions
1241
* Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
1242
* Support for Epoch data channel on Windows, using the win-dco driver (2.8.0+)
1243
* "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
1244
* COPYING: license details only relevant to our Windows installers have been updated and moved to the openvpn-build repo
1245
1246
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_rc2/Changes.rst)
1247
1248
Windows MSI changes since 2.7_rc1:
1249
* Built against OpenSSL 3.6.0
1250
* Included openvpn-gui updated to 11.58.0.0
1251
* Check the return value of GetProp()
1252
* Make config path check similar to that in interactive service
1253
* Escape the type id of password message received from openvpn
1254
* Add a message source for event logging
1255
* Check correct management daemon path when OpenVPN3 is enabled
1256
* Fix OpenVPN3 radio button label size when OVPN3 is enabled
1257
* Use GetTempPath() for debug file in plap as well
1258
* Migrate all saved plain usernames to encrypted format
1259
* Included win-dco driver updated to 2.8.0
1260
1261
| | | |
1262
|-|-|-|
1263
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc2-I009-amd64.msi.asc)|[OpenVPN-2.7_rc2-I009-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc2-I009-amd64.msi)|
1264
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc2-I009-arm64.msi.asc)|[OpenVPN-2.7_rc2-I009-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc2-I009-arm64.msi)|
1265
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc2-I009-x86.msi.asc)|[OpenVPN-2.7_rc2-I009-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc2-I009-x86.msi)|
1266
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc2.tar.gz.asc)|[openvpn-2.7_rc2.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc2.tar.gz)|
1267
1268
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
1269
1270
## OpenVPN 2.6.16 -- Released 17 November 2025
1271
The OpenVPN community project team is proud to release OpenVPN 2.6.16. This is a bugfix release containing one security fix.
1272
1273
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.16/Changes.rst)
1274
1275
Security fixes:
1276
1277
* [CVE-2025-13086](https://www.cve.org/CVERecord?id=CVE-2025-13086): Fix memcmp check for the hmac verification in the 3way handshake.
1278
This bug renders the HMAC based protection against state exhaustion on
1279
receiving spoofed TLS handshake packets in the OpenVPN server inefficient.
1280
1281
Bug fixes:
1282
1283
* fix invalid pointer creation in tls_pre_decrypt() - technically this is
1284
a memory over-read issue, in practice, the compilers optimize it away
1285
so no negative effects could be observed.
1286
* Windows: in the interactive service, fix the "undo DNS config" handling.
1287
* Windows: in the interactive service, disallow using of "stdin" for the
1288
config file, unless the caller is authorized OpenVPN Administrator
1289
* Windows: in the interactive service, change all netsh calls to use
1290
interface index and not interface name - sidesteps all possible attack
1291
avenues with special characters in interface names.
1292
* Windows: in the interactive service, improve error handling in
1293
some "unlikely to happen" paths.
1294
* auth plugin/script handling: properly check for errors in creation on
1295
$auth_failed_reason_file (arf).
1296
* for incoming TCP connections, close-on-exec option was applied to
1297
the wrong socket fd, leaking socket FDs to child processes.
1298
* sitnl: set close-on-exec flag on netlink socket
1299
* ssl_mbedtls: fix missing perf_pop() call (optional performance profiling)
1300
1301
Windows MSI changes since 2.6.15-I001:
1302
* Built against OpenSSL 3.6.0
1303
* Included openvpn-gui updated to 11.58.0.0
1304
* Check the return value of GetProp()
1305
* Make config path check similar to that in interactive service
1306
* Escape the type id of password message received from openvpn
1307
* Add a message source for event logging
1308
* Check correct management daemon path when OpenVPN3 is enabled
1309
* Fix OpenVPN3 radio button label size when OVPN3 is enabled
1310
* Use GetTempPath() for debug file in plap as well
1311
* Migrate all saved plain usernames to encrypted format
1312
* Included win-dco driver updated to 2.8.0
1313
1314
| | | |
1315
|-|-|-|
1316
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.16-I001-amd64.msi.asc)|[OpenVPN-2.6.16-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.16-I001-amd64.msi)|
1317
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.16-I001-arm64.msi.asc)|[OpenVPN-2.6.16-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.16-I001-arm64.msi)|
1318
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.16-I001-x86.msi.asc)|[OpenVPN-2.6.16-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.16-I001-x86.msi)|
1319
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.16.tar.gz.asc)|[openvpn-2.6.16.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.16.tar.gz)|
1320
1321
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
1322
841f03 uddr 2025-10-31 15:32:51 1323
## OpenVPN 2.7_rc1 -- Released 31 October 2025
1324
The OpenVPN community project team is proud to release OpenVPN 2.7_rc1. This is the first release candidate for the feature release 2.7.0.
1325
1326
Feature changes since 2.7_beta3:
1327
* add warning for unsupported combination of --push and --tls-server
1328
* add warning for unsupported combination of `--reneg-bytes` or `--reneg-pkts` with DCO
1329
* remove perf_push()/perf_pop() infrastructure (because it did not work anymore, and compiler profiling will give better results today)
1330
* ensure compatibility with OpenSSL 3.6.0 - specifically, do not crash in t_lpback.sh trying to use new encrypt-then-mac (ETM) ciphers
1331
* improved PUSH_UPDATE server side support, which now handles changes of pushed ifconfig/ifconfig-ipv6 addresses correctly (send packets to new IP addresses to this client, stop sending packets to the old addresses).
1332
* freshen URLs all over the tree, and change to HTTPS where possible
1333
* on DCO Linux/FreeBSD, add support for clients receiving an IPv4/IPv6 address that is not part of the --server/--server-ipv6 subnet (= install extra on-interface host routes).
1334
* Windows programs use a new API for path name canonicalization now (PathCchCanonicalizeEx()) which will break building with MinGW on Ubuntu 22.04 -> Upgrade to 24.04 to make builds work again.
1335
* on Windows, when setting up WINS servers using netsh, use interface index instead of adapter name now ("as for all other netsh calls")
1336
* remove undocumented and unused --memstats feature
1337
1338
Important bug fixes since 2.7_beta3:
1339
* even more type conversion related warnings have been fixed
1340
* more bugfixes related to BYTECOUNT display on the management interface and byte counters on DCO platforms in general
1341
* numerous minibugs reported by ZeroPath AI have been fixed (small memleaks, possible file descriptor leaks, improved sanity checks, add ASSERT() on function contracts, etc.)
1342
1343
For a list of all changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_beta3...v2.7_rc1).
1344
1345
Highlights of 2.7 include:
1346
* Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
1347
* Improved Client support for DNS options
1348
* Client implementations for Linux/BSD/macOS, included with the default install
1349
* New client implementation for Windows, adding support for features like split DNS and DNSSEC
1350
* Architectural improvements on Windows
1351
* The `block-local` flag is now enforced with WFP filters
1352
* Windows network adapters are now generated on demand
1353
* Windows automatic service now runs as an unpriviledged user
1354
* Support for server mode in win-dco driver
1355
* Note: Support for the wintun driver has been removed. win-dco is now the default, tap-windows6 is the fallback solution for use-cases not covered by win-dco.
1356
* Improved data channel
1357
* Enforcement of AES-GCM usage limit
1358
* Epoch data keys and packet format
1359
* Support for new upstream DCO Linux kernel module
1360
* This release supports the new `ovpn` DCO Linux kernel module which will be available in future upstream Linux kernel releases. Backports of the new module to current kernels are available via the [ovpn-backports project](https://github.com/OpenVPN/ovpn-backports).
1361
* Client-side support for new `PUSH_UPDATE` control-channel message
1362
* This allows servers to send updates to options like routing and DNS config without triggering a reconnect.
1363
* PUSH_UPDATE server support (minimal)
1364
* New management interface commands `push-update-broad` and `push-update-cid` to send PUSH_UPDATE option updates.
1365
* TLS 1.3 support with bleeding-edge mbedTLS versions
1366
* Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
1367
* Support for Epoch data channel on Windows, using the win-dco driver (2.8.0+)
1368
* "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
1369
* COPYING: license details only relevant to our Windows installers have been updated and moved to the openvpn-build repo
1370
1371
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_rc1/Changes.rst)
1372
1373
Windows MSI changes since 2.7_beta3:
1374
* Built against OpenSSL 3.6.0
1375
* Included openvpn-gui updated to 11.57.0.0
1376
* Encrypt username saved in registry
1377
* Avoid blocking calls during WM_OVPN_ECHOMSG processing
1378
* Fixes segfault when echo msg-notify happens with no message to display (Github: [OpenVPN/openvpn-gui#771](https://github.com/OpenVPN/openvpn-gui/issues/771))
1379
* Check the path of the process listening on management port
1380
* Error out if imported profile file name is too long
1381
* Disallow Windows special filenames for imported profile
1382
* Replace % characters in param->id as it's used in format template
1383
* Excplicitly check that urls start with http:// or https://
1384
* Included win-dco driver updated to 2.8.0
1385
1386
| | | |
1387
|-|-|-|
1388
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc1-I008-amd64.msi.asc)|[OpenVPN-2.7_rc1-I008-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc1-I008-amd64.msi)|
1389
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc1-I008-arm64.msi.asc)|[OpenVPN-2.7_rc1-I008-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc1-I008-arm64.msi)|
1390
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc1-I008-x86.msi.asc)|[OpenVPN-2.7_rc1-I008-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_rc1-I008-x86.msi)|
1391
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc1.tar.gz.asc)|[openvpn-2.7_rc1.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7_rc1.tar.gz)|
1392
1393
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
1394
0a4a6d uddr 2025-10-13 15:22:13 1395
## OpenVPN 2.7_beta3 -- Released 13 October 2025
1396
The OpenVPN community project team is proud to release OpenVPN 2.7_beta3. This is the third Beta release for the feature release 2.7.0. As the Beta name implies this is an early release build, it is not intended for production use.
1397
1398
Feature changes since 2.7_beta2:
1399
* improvements on PUSH_UPDATE handling on the server side
1400
* improve "recursive routing checks", prepare the way for a policy-based setup where "packets to VPN server" could end up in the tunnel without interfering with OpenVPN operations
1401
* add support for "eoch" data format to DCO on Windows (needs dco-win driver 2.8.0+)
1402
* clean up and remove outdated stuff from COPYING
1403
1404
Important bug fixes since 2.7_beta2:
1405
* bugfixes reconnect and PUSH_UPDATE handling on the client side (notably handling of ifconfig/ifconfig-ipv6/redirect-gateway ipv6 if the server is not always pushing the same address families)
1406
1407
For a list of all changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_beta2...v2.7_beta3).
1408
1409
Highlights of 2.7 include:
1410
* Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
1411
* Improved Client support for DNS options
1412
* Client implementations for Linux/BSD/macOS, included with the default install
1413
* New client implementation for Windows, adding support for features like split DNS and DNSSEC
1414
* Architectural improvements on Windows
1415
* The `block-local` flag is now enforced with WFP filters
1416
* Windows network adapters are now generated on demand
1417
* Windows automatic service now runs as an unpriviledged user
1418
* Support for server mode in win-dco driver
1419
* Note: Support for the wintun driver has been removed. win-dco is now the default, tap-windows6 is the fallback solution for use-cases not covered by win-dco.
1420
* Improved data channel
1421
* Enforcement of AES-GCM usage limit
1422
* Epoch data keys and packet format
1423
* Support for new upstream DCO Linux kernel module
1424
* This release supports the new `ovpn` DCO Linux kernel module which will be available in future upstream Linux kernel releases. Backports of the new module to current kernels are available via the [ovpn-backports project](https://github.com/OpenVPN/ovpn-backports).
1425
* Client-side support for new `PUSH_UPDATE` control-channel message
1426
* This allows servers to send updates to options like routing and DNS config without triggering a reconnect.
1427
* PUSH_UPDATE server support (minimal)
1428
* New management interface commands `push-update-broad` and `push-update-cid` to send PUSH_UPDATE option updates.
1429
* TLS 1.3 support with bleeding-edge mbedTLS versions
1430
* Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
1431
* Support for Epoch data channel on Windows, using the win-dco driver (2.8.0+)
1432
* "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
1433
* COPYING: license details only relevant to our Windows installers havebeen updated and moved to the openvpn-build repo
1434
1435
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_beta3/Changes.rst)
1436
1437
Windows MSI changes since 2.7_beta2:
1438
* Built against OpenSSL 3.6.0
1439
* Included openvpn-gui updated to 11.56.0.0
1440
* Included win-dco driver updated to 2.8.0
1441
1442
| | | |
1443
|-|-|-|
1444
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_beta3-I007-amd64.msi.asc)|[OpenVPN-2.7_beta3-I007-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_beta3-I007-amd64.msi)|
1445
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_beta3-I007-arm64.msi.asc)|[OpenVPN-2.7_beta3-I007-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_beta3-I007-arm64.msi)|
1446
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_beta3-I007-x86.msi.asc)|[OpenVPN-2.7_beta3-I007-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_beta3-I007-x86.msi)|
1447
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7_beta3.tar.gz.asc)|[openvpn-2.7_beta3.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7_beta3.tar.gz)|
1448
1449
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
1450
e40f74 uddr 2025-09-25 08:51:47 1451
## OpenVPN 2.7_beta2 -- Released 25 September 2025
1452
The OpenVPN community project team is proud to release OpenVPN 2.7_beta2. This is the second Beta release for the feature release 2.7.0. As the Beta name implies this is an early release build, it is not intended for production use.
1453
1454
Feature changes since 2.7_beta1:
1455
* greatly improved event log handling for the Windows interactive service - this brings build system changes and a new openvpnservmsg.dll
1456
1457
Important bug fixes since 2.7_beta1:
1458
* add proper input sanitation to DNS strings to prevent an attack coming from a trusted-but-malicous OpenVPN server ([CVE-2025-10680](https://www.cve.org/CVERecord?id=CVE-2025-10680), affects unixoid systems with `--dns-updown` scripts and windows using the built-in powershell call)
1459
* bugfixes when using multi-socket on windows (properly recognize that TCP server mode does not work with DCO, properly handle TCP multi-socket server setups without DCO)
1460
* bring back configuring of IPv4 broadcast addresses on Linux
1461
* repair "--dhcp-option DNS" setting in combination with DHCP (TAP) or "--up" scripts (Github: [OpenVPN/openvpn#839](https://github.com/OpenVPN/openvpn/issues/839), [OpenVPN/openvpn#840](https://github.com/OpenVPN/openvpn/issues/840))
1462
1463
For a list of all changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_beta1...v2.7_beta2).
1464
1465
Highlights of 2.7 include:
1466
* Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
1467
* Improved Client support for DNS options
1468
* Client implementations for Linux/BSD/macOS, included with the default install
1469
* New client implementation for Windows, adding support for features like split DNS and DNSSEC
1470
* Architectural improvements on Windows
1471
* The `block-local` flag is now enforced with WFP filters
1472
* Windows network adapters are now generated on demand
1473
* Windows automatic service now runs as an unpriviledged user
1474
* Support for server mode in win-dco driver
1475
* Note: Support for the wintun driver has been removed. win-dco is now the default, tap-windows6 is the fallback solution for use-cases not covered by win-dco.
1476
* Improved data channel
1477
* Enforcement of AES-GCM usage limit
1478
* Epoch data keys and packet format
1479
* Support for new upstream DCO Linux kernel module
1480
* This release supports the new `ovpn` DCO Linux kernel module which will be available in future upstream Linux kernel releases. Backports of the new module to current kernels are available via the [ovpn-backports project](https://github.com/OpenVPN/ovpn-backports).
1481
* Client-side support for new `PUSH_UPDATE` control-channel message
1482
* This allows servers to send updates to options like routing and DNS config without triggering a reconnect.
1483
* PUSH_UPDATE server support (minimal)
1484
* New management interface commands `push-update-broad` and `push-update-cid` to send PUSH_UPDATE option updates.
1485
* TLS 1.3 support with bleeding-edge mbedTLS versions
1486
* Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
1487
1488
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_beta2/Changes.rst)
1489
1490
Windows MSI changes since 2.7_beta1:
1491
* Built against OpenSSL 3.5.3
1492
* Included openvpn-gui updated to 11.56.0.0
1493
* Fix "Cannot open the System Tray Menu with Keyboard" (Github: [OpenVPN/openvpn-gui#763](https://github.com/OpenVPN/openvpn-gui/issues/763))
1494
1495
| | | |
1496
|-|-|-|
1497
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_beta2-I006-amd64.msi.asc)|[OpenVPN-2.7_beta2-I006-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_beta2-I006-amd64.msi)|
1498
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_beta2-I006-arm64.msi.asc)|[OpenVPN-2.7_beta2-I006-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_beta2-I006-arm64.msi)|
1499
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_beta2-I006-x86.msi.asc)|[OpenVPN-2.7_beta2-I006-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_beta2-I006-x86.msi)|
1500
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7_beta2.tar.gz.asc)|[openvpn-2.7_beta2.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7_beta2.tar.gz)|
1501
1502
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
1503
2bdbc6 flichtenheld 2025-09-22 14:18:49 1504
## OpenVPN 2.6.15 -- Released 22 September 2025
1505
The OpenVPN community project team is proud to release OpenVPN 2.6.15. This is a bugfix release.
1506
1507
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.15/Changes.rst)
1508
1509
Bug fixes:
1510
1511
* on Windows, do not use "wmic.exe" any longer to set DNS search domain
1512
(discontinued by Microsoft), use "powershell" fragment instead.
1513
* on Windows, logging to the windows event log has been improved
1514
(and logging of GetLastError() strings repaired). To make this work,
1515
a new "openvpnmsgserv.dll" library is now installed and registered.
1516
* DNS domain names are now strictly validated with a positive-list of
1517
allowed characters (including UTF-8 high-bit-set bytes) before being
1518
handed to powershell.
1519
* Apply more checks to incoming TLS handshake packets before creating
1520
new state - namely, verify message ID / acked ID for "valid range for
1521
an initial packet". This fixes a problem with clients that float
1522
very early but send control channel packet from the pre-float IP
1523
(Github: [OpenVPN/openvpn#704](https://github.com/OpenVPN/openvpn/issues/704),
1524
backported from 2.7_beta1.
1525
* backport handling of client float notifications on FreeBSD 14/STABLE DCO
1526
(see https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=289303)
1527
* update GPL license text to latest version from FSF
1528
* on Linux, on interfaces where applicable, OpenVPN explicitly configures
1529
the broadcast address again. This was dropped for 2.6.0 "because
1530
computers are smart and can do it themselves", but the kernel netlink
1531
interface isn't, and will install "0.0.0.0". This does not normally
1532
matter, but for broadcast-based applications that get the address to
1533
use from "ifconfig", this change repairs functionality.
1534
1535
Windows MSI changes since 2.6.14-I004:
1536
* Built against OpenSSL 3.5.3
1537
* Included openvpn-gui updated to 11.56.0.0
1538
* Fix "Cannot open the System Tray Menu with Keyboard" (Github: [OpenVPN/openvpn-gui#763](https://github.com/OpenVPN/openvpn-gui/issues/763))
1539
1540
| | | |
1541
|-|-|-|
1542
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.15-I001-amd64.msi.asc)|[OpenVPN-2.6.15-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.15-I001-amd64.msi)|
1543
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.15-I001-arm64.msi.asc)|[OpenVPN-2.6.15-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.15-I001-arm64.msi)|
1544
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.15-I001-x86.msi.asc)|[OpenVPN-2.6.15-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.15-I001-x86.msi)|
1545
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.15.tar.gz.asc)|[openvpn-2.6.15.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.15.tar.gz)|
1546
1547
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
1548
11d54c uddr 2025-09-04 12:57:59 1549
## OpenVPN 2.7_beta1 -- Released 04 September 2025
1550
The OpenVPN community project team is proud to release OpenVPN 2.7_beta1. This is the first Beta release for the feature release 2.7.0. As the Beta name implies this is an early release build, it is not intended for production use.
1551
1552
Feature changes since 2.7_alpha3:
1d4b79 uddr 2025-09-04 13:04:21 1553
* Introduction of `route_redirect_gateway_ipv4` and `_ipv6` env variables
11d54c uddr 2025-09-04 12:57:59 1554
* PUSH_UPDATE server support (via management interface)
1555
* Rewrite of the management interface "bytecount" infastructure to better interact with DCO
1556
1557
Important bug fixes since 2.7_alpha3:
1d4b79 uddr 2025-09-04 13:04:21 1558
* Bugfixes in `--dns-updown` script for linux systems using resolvconf
11d54c uddr 2025-09-04 12:57:59 1559
* A large number of signed/unsigned related warnings have been fixed
1560
1561
For a list of all changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_alpha3...v2.7_beta1).
1562
1563
Highlights of 2.7 include:
1564
* Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
1565
* Improved Client support for DNS options
1566
* Client implementations for Linux/BSD/macOS, included with the default install
1567
* New client implementation for Windows, adding support for features like split DNS and DNSSEC
1568
* Architectural improvements on Windows
1569
* The `block-local` flag is now enforced with WFP filters
1570
* Windows network adapters are now generated on demand
1571
* Windows automatic service now runs as an unpriviledged user
1572
* Support for server mode in win-dco driver
1573
* Note: Support for the wintun driver has been removed. win-dco is now the default, tap-windows6 is the fallback solution for use-cases not covered by win-dco.
1574
* Improved data channel
1575
* Enforcement of AES-GCM usage limit
1576
* Epoch data keys and packet format
1577
* Support for new upstream DCO Linux kernel module
1578
* This release supports the new `ovpn` DCO Linux kernel module which will be available in future upstream Linux kernel releases. Backports of the new module to current kernels are available via the [ovpn-backports project](https://github.com/OpenVPN/ovpn-backports).
1579
* Client-side support for new `PUSH_UPDATE` control-channel message
1580
* This allows servers to send updates to options like routing and DNS config without triggering a reconnect.
1581
* PUSH_UPDATE server support (minimal)
1582
* New management interface commands `push-update-broad` and `push-update-cid` to send PUSH_UPDATE option updates.
1583
* TLS 1.3 support with bleeding-edge mbedTLS versions
1584
* Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
1585
1586
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_beta1/Changes.rst)
1587
1588
Windows MSI changes since 2.7_alpha3:
1589
* Included dco-win driver updated to 2.7.1
1590
* add support for multipeer stats
1591
* Built against OpenSSL 3.5.1
1592
* Included openvpn-gui 11.55.0.0
1593
1594
| | | |
1595
|-|-|-|
7764dc uddr 2025-09-05 06:31:42 1596
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_beta1-I005-amd64.msi.asc)|[OpenVPN-2.7_beta1-I005-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_beta1-I005-amd64.msi)|
1597
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_beta1-I005-arm64.msi.asc)|[OpenVPN-2.7_beta1-I005-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_beta1-I005-arm64.msi)|
1598
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_beta1-I005-x86.msi.asc)|[OpenVPN-2.7_beta1-I005-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_beta1-I005-x86.msi)|
11d54c uddr 2025-09-04 12:57:59 1599
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7_beta1.tar.gz.asc)|[openvpn-2.7_beta1.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7_beta1.tar.gz)|
1600
1601
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
1602
3ed674 flichtenheld 2025-08-01 11:54:46 1603
## OpenVPN 2.7_alpha3 -- Released 31 July 2025
1604
The OpenVPN community project team is proud to release OpenVPN 2.7_alpha3. This is the third Alpha release for the feature release 2.7.0. As the Alpha name implies this is an early release build, it is not intended for production use.
1605
1606
Feature changes since 2.7_alpha2:
1607
* ``--dns-updown`` script for macOS
1608
* Client-side support for PUSH_UPDATE handling
1609
* Support for floating TLS clients when DCO is active (requires latest versions of DCO drivers)
1610
* Use of user-defined routing tables on Linux
1611
* PQE support for WolfSSL
1612
1613
Important bug fixes since 2.7_alpha2:
1614
* Fix issue in handling DCO messages on Linux that could lead to various problems due to unhandled messages
1615
* Fix issues with DHCP on Windows with tap driver
1616
60384b flichtenheld 2025-08-01 11:58:55 1617
For a list of all changes in Alpha 3 changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_alpha2...v2.7_alpha3).
3ed674 flichtenheld 2025-08-01 11:54:46 1618
60384b flichtenheld 2025-08-01 11:58:55 1619
For details about 2.7 features see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_alpha3/Changes.rst)
3ed674 flichtenheld 2025-08-01 11:54:46 1620
1621
Windows MSI changes since 2.7_alpha3:
1622
* win-dco driver updated from 2.5.9 to 2.6.2
1623
* Adds float support
1624
* Built against OpenSSL 3.5.1
1625
* Included openvpn-gui updated to 11.55.0.0
1626
* Fix Chinese localization for OpenVPN GUI
1627
1628
| | | |
1629
|-|-|-|
1630
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_alpha3-I004-amd64.msi.asc)|[OpenVPN-2.7_alpha3-I004-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_alpha3-I004-amd64.msi)|
1631
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_alpha3-I004-arm64.msi.asc)|[OpenVPN-2.7_alpha3-I004-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_alpha3-I004-arm64.msi)|
1632
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_alpha3-I004-x86.msi.asc)|[OpenVPN-2.7_alpha3-I004-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_alpha3-I004-x86.msi)|
1633
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7_alpha3.tar.gz.asc)|[openvpn-2.7_alpha3.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7_alpha3.tar.gz)|
1634
1635
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
1636
a891da uddr 2025-06-19 18:48:57 1637
## OpenVPN 2.7_alpha2 -- Released 19 June 2025
32d161 uddr 2025-06-20 13:34:15 1638
The OpenVPN community project team is proud to release OpenVPN 2.7_alpha2. This is the second Alpha release containing bugfixes and one security fix for the feature release 2.7.0. As the Alpha name implies this is an early release build, this is not intended for production use.
a891da uddr 2025-06-19 18:48:57 1639
32d161 uddr 2025-06-20 13:34:15 1640
New feature since 2.7_alpha1:
1641
* TLS 1.3 support with bleeding-edge mbedTLS versions
1642
60384b flichtenheld 2025-08-01 11:58:55 1643
For a list of all changes in Alpha 2 changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_alpha1...v2.7_alpha2).
1644
1645
For details about 2.7 features see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_alpha2/Changes.rst)
32d161 uddr 2025-06-20 13:34:15 1646
1647
Windows MSI changes since 2.7_alpha1:
021418 novaflash 2025-07-02 12:28:58 1648
* Includes fix for [CVE-2025-50054](https://www.cve.org/CVERecord?id=CVE-2025-50054)
32d161 uddr 2025-06-20 13:34:15 1649
* Built against OpenSSL 3.5.0
1650
* Included openvpn-gui updated to 11.54.0.0
1651
* Improve French (fr) and Turkish (tr) localization for OpenVPN GUI
1652
1653
| | | |
1654
|-|-|-|
891b5a uddr 2025-06-30 12:43:56 1655
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_alpha2-I003-amd64.msi.asc)|[OpenVPN-2.7_alpha2-I003-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_alpha2-I003-amd64.msi)|
1656
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_alpha2-I003-arm64.msi.asc)|[OpenVPN-2.7_alpha2-I003-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_alpha2-I003-arm64.msi)|
1657
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_alpha2-I003-x86.msi.asc)|[OpenVPN-2.7_alpha2-I003-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_alpha2-I003-x86.msi)|
32d161 uddr 2025-06-20 13:34:15 1658
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7_alpha2.tar.gz.asc)|[openvpn-2.7_alpha2.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7_alpha2.tar.gz)|
1659
1660
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
1661
1662
## OpenVPN 2.7_alpha1 -- Released 28 May 2025
1663
The OpenVPN community project team is proud to release OpenVPN 2.7_alpha1. This is the first Alpha release for the feature release 2.7.0. As the Alpha name implies this is an early release build, this is not intended for production use.
7f6e4e flichtenheld 2025-05-28 21:08:06 1664
1665
Highlights of this release include:
1666
* Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
1667
* Improved Client support for DNS options
1668
* Client implementations for Linux/BSD, included with the default install
1e8577 flichtenheld 2025-05-28 21:39:29 1669
* New client implementation for Windows, adding support for features like split DNS and DNSSEC
7f6e4e flichtenheld 2025-05-28 21:08:06 1670
* Architectural improvements on Windows
1671
* The `block-local` flag is now enforced with WFP filters
1672
* Windows network adapters are now generated on demand
1673
* Windows automatic service now runs as an unpriviledged user
1674
* Support for server mode in win-dco driver
18cae3 flichtenheld 2025-05-28 21:23:16 1675
* Note: Support for the wintun driver has been removed. win-dco is now the default, tap-windows6 is the fallback solution for use-cases not covered by win-dco.
7f6e4e flichtenheld 2025-05-28 21:08:06 1676
* Improved data channel
1677
* Enforcement of AES-GCM usage limit
1678
* Epoch data keys and packet format
1e8577 flichtenheld 2025-05-28 21:39:29 1679
* Support for new upstream DCO Linux kernel module
1680
* This release supports the new `ovpn` DCO Linux kernel module which will be available in future upstream Linux kernel releases. Backports of the new module to current kernels are available via the [ovpn-backports project](https://github.com/OpenVPN/ovpn-backports).
7f6e4e flichtenheld 2025-05-28 21:08:06 1681
32d161 uddr 2025-06-20 13:34:15 1682
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_alpha1/Changes.rst)
7f6e4e flichtenheld 2025-05-28 21:08:06 1683
1684
Windows MSI changes since 2.6.14:
1685
* Built against OpenSSL 3.5.0
32d161 uddr 2025-06-20 13:34:15 1686
* Included openvpn-gui updated to 11.53.0.0
7f6e4e flichtenheld 2025-05-28 21:08:06 1687
* Support for webauth in PLAP (Pre-Logon Access Provider) via QR code (github [openvpn-gui#687](https://github.com/OpenVPN/openvpn-gui/issues/687))
1688
1689
| | | |
1690
|-|-|-|
32d161 uddr 2025-06-20 13:34:15 1691
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_alpha1-I001-amd64.msi.asc)|[OpenVPN-2.7_alpha1-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_alpha1-I001-amd64.msi)|
1692
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_alpha1-I001-arm64.msi.asc)|[OpenVPN-2.7_alpha1-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_alpha1-I001-arm64.msi)|
1693
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_alpha1-I001-x86.msi.asc)|[OpenVPN-2.7_alpha1-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7_alpha1-I001-x86.msi)|
1694
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7_alpha1.tar.gz.asc)|[openvpn-2.7_alpha1.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7_alpha1.tar.gz)|
7f6e4e flichtenheld 2025-05-28 21:08:06 1695
3c87e8 flichtenheld 2025-05-28 21:16:43 1696
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
7f6e4e flichtenheld 2025-05-28 21:08:06 1697
76927e uddr 2025-04-02 17:21:23 1698
## OpenVPN 2.6.14 -- Released 02 April 2025
1699
The OpenVPN community project team is proud to release OpenVPN 2.6.14. This is a bugfix release containing one security fix.
1700
1701
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.14/Changes.rst)
1702
1703
Security fixes:
1704
021418 novaflash 2025-07-02 12:28:58 1705
* [CVE-2025-2704](https://www.cve.org/CVERecord?id=CVE-2025-2704): fix possible `ASSERT()` on OpenVPN servers using `--tls-crypt-v2`
76927e uddr 2025-04-02 17:21:23 1706
Security scope: OpenVPN servers between 2.6.1 and 2.6.13 using
1707
`--tls-crypt-v2` can be made to abort with an `ASSERT()` message by
1708
sending a particular combination of authenticated and malformed packets.
1709
To trigger the bug, a valid tls-crypt-v2 client key is needed, or
1710
network observation of a handshake with a valid tls-crypt-v2 client key.
1711
No crypto integrity is violated, no data is leaked, and no remote
1712
code execution is possible.
1713
This bug does not affect OpenVPN clients.
1714
(Bug found by internal QA at OpenVPN Inc)
1715
1716
Bug fixes:
1717
1718
* Linux DCO: repair source IP selection for `--multihome` (Qingfang Deng)
1719
1720
Windows MSI changes since 2.6.13:
1721
* Built against OpenSSL 3.4.1
1722
* Included openvpn-gui updated to 11.52.0.0
1723
* Use correct `%TEMP%` directory for debug log file.
1724
* Disable config in menu listing if its ovpn file becomes inaccessible (github [openvpn-gui#729](https://github.com/OpenVPN/openvpn-gui/issues/729))
1725
dabdb6 uddr 2025-06-19 15:52:55 1726
Note: Windows MSI was updated to I002 on June 19th. Changes in I002:
021418 novaflash 2025-07-02 12:28:58 1727
* Includes fix for [CVE-2025-50054](https://www.cve.org/CVERecord?id=CVE-2025-50054)
1fe933 flichtenheld 2025-08-04 13:54:41 1728
* Built against OpenSSL 3.5.0
1729
* Included openvpn-gui updated to 11.54.0.0
1730
* Support for webauth in PLAP (Pre-Logon Access Provider) via QR code (github [openvpn-gui#687](https://github.com/OpenVPN/openvpn-gui/issues/687))
1731
* Improve French (fr) and Turkish (tr) localization for OpenVPN GUI
1732
* Included dco-win driver updated to 1.3.1
1733
1734
Note: Windows MSI was update to I003 on August 4th. Changes in I003:
1735
* Built against OpenSSL 3.5.1
1736
* Included openvpn-gui updated to 11.55.0.0
1737
* Fix Chinese localization for OpenVPN GUI
1738
* Included dco-win driver updated to 1.3.2
dabdb6 uddr 2025-06-19 15:52:55 1739
62ad76 uddr 2025-08-06 14:40:57 1740
Note: Windows MSI was updated to I004 on August 6th. Changes in I004:
1741
* Included dco-win driver updated to 1.3.3
1742
* Fix for recursive routing behavior
1743
76927e uddr 2025-04-02 17:21:23 1744
| | | |
1745
|-|-|-|
62ad76 uddr 2025-08-06 14:40:57 1746
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.14-I004-amd64.msi.asc)|[OpenVPN-2.6.14-I004-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.14-I004-amd64.msi)|
1747
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.14-I004-arm64.msi.asc)|[OpenVPN-2.6.14-I004-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.14-I004-arm64.msi)|
1748
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.14-I004-x86.msi.asc)|[OpenVPN-2.6.14-I003-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.14-I004-x86.msi)|
76927e uddr 2025-04-02 17:21:23 1749
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.14.tar.gz.asc)|[openvpn-2.6.14.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.14.tar.gz)|
1750
3c87e8 flichtenheld 2025-05-28 21:16:43 1751
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).
76927e uddr 2025-04-02 17:21:23 1752
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1753
## OpenVPN 2.6.13 -- Released 15 January 2025
c14e58 Samuli Seppänen 2025-02-11 07:05:53 1754
The OpenVPN community project team is proud to release OpenVPN 2.6.13. This is a bugfix release.
1755
1756
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.13/Changes.rst)
1757
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1758
Feature changes:
1759
1760
* on non-windows clients (MacOS, Linux, Unix) send "release" string from
1761
`uname()` call as `IV_PLAT_VER` to server - while highly OS specific this
1762
is still helpful to keep track of OS versions used on the client side
1763
(github [#637](https://github.com/OpenVPN/openvpn/issues/637))
1764
* Windows: protect cached username, password and token in client memory
1765
(using the `CryptProtectMemory()` windows API)
1766
* Windows: use new API to get dco-win driver version from driver
1767
(newly introduced non-exclusive control device) (github [ovpn-dco-win#76](https://github.com/OpenVPN/ovpn-dco-win/issues/76))
1768
* Linux: pass `--timeout=0 argument` to `systemd-ask-password`, to avoid
1769
default timeout of 90 seconds ("console prompting also has no timeout")
1770
(github [#649](https://github.com/OpenVPN/openvpn/issues/649))
1771
1772
Security fixes:
1773
1774
* improve server-side handling of clients sending usernames or passwords
1775
longer than `USER_PASS_LEN` - this would not result in a crash, buffer
1776
overflow or other security issues, but the server would then misparse
1777
incoming IV variables and produce misleading error messages.
1778
1779
Notable bug fixes:
1780
1781
* FreeBSD DCO: fix memory leaks in nvlist handling (github [#636](https://github.com/OpenVPN/openvpn/issues/636))
1782
* purge proxy authentication credentials from memory after use
1783
(if `--auth-nocache` is in use)
1784
1785
Windows MSI changes since 2.6.12:
1786
* Built against OpenSSL 3.4.0
1787
* Included openvpn-gui updated to 11.51.0.0
1788
* Higher resolution eye icons (github [openvpn-gui#697](https://github.com/OpenVPN/openvpn-gui/issues/697))
1789
* Support for concatenating OTP with password
1790
* Optionally always prompt for OTP
1791
* Fix tooltip positioning when the taskbar is at top (github [openvpn-gui#710](https://github.com/OpenVPN/openvpn-gui/issues/710))
c14e58 Samuli Seppänen 2025-02-11 07:05:53 1792
3c87e8 flichtenheld 2025-05-28 21:16:43 1793
Debian/Ubuntu packages in [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos) are now available for Ubuntu 24.10 (oracular).
c14e58 Samuli Seppänen 2025-02-11 07:05:53 1794
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1795
| | | |
1796
|-|-|-|
1797
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.13-I001-amd64.msi.asc)|[OpenVPN-2.6.13-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.13-I001-amd64.msi)|
1798
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.12-I001-arm64.msi.asc)|[OpenVPN-2.6.13-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.13-I001-arm64.msi)|
1799
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.13-I001-x86.msi.asc)|[OpenVPN-2.6.13-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.13-I001-x86.msi)|
1800
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.13.tar.gz.asc)|[openvpn-2.6.13.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.13.tar.gz)|
c14e58 Samuli Seppänen 2025-02-11 07:05:53 1801
1802
For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
1803
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1804
## OpenVPN 2.5.11 -- Released 18 July 2024
1805
The OpenVPN community project team is proud to release OpenVPN 2.5.11. This is a security fix release.
c14e58 Samuli Seppänen 2025-02-11 07:05:53 1806
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1807
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.5.11/Changes.rst)
c14e58 Samuli Seppänen 2025-02-11 07:05:53 1808
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1809
Security fixes:
c14e58 Samuli Seppänen 2025-02-11 07:05:53 1810
021418 novaflash 2025-07-02 12:28:58 1811
- [CVE-2024-5594](https://www.cve.org/CVERecord?id=CVE-2024-5594): control channel: refuse control channel messages with
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1812
nonprintable characters in them. Security scope: a malicious openvpn peer can send garbage to openvpn log, or cause high CPU load.
1813
(Reynir Björnsson)
c14e58 Samuli Seppänen 2025-02-11 07:05:53 1814
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1815
(Backport of the security fix in 2.6.11 and the fix for the bugfix
1816
in 2.6.12)
c14e58 Samuli Seppänen 2025-02-11 07:05:53 1817
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1818
In accordance with our [support policy](/SupportedVersions) packages and installers are not provided for 2.5 anymore.
c14e58 Samuli Seppänen 2025-02-11 07:05:53 1819
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1820
| | | |
1821
|-|-|-|
1822
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.5.11.tar.gz.asc)|[openvpn-2.5.11.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.5.11.tar.gz)|
c14e58 Samuli Seppänen 2025-02-11 07:05:53 1823
1824
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1825
## OpenVPN 2.6.12 -- Released 18 July 2024
1826
The OpenVPN community project team is proud to release OpenVPN 2.6.12. This is a bugfix release.
1827
1828
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.12/Changes.rst)
c14e58 Samuli Seppänen 2025-02-11 07:05:53 1829
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1830
Bug fixes:
c14e58 Samuli Seppänen 2025-02-11 07:05:53 1831
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1832
* the fix for CVE-2024-5594 (refuse control channel messages with
1833
nonprintable characters) was too strict, breaking user configurations
1834
with AUTH_FAIL messages having trailing CR/NL characters. This often
1835
happens if the AUTH_FAIL reason is set by a script. Strip those before
1836
testing the command buffer (github [#568](https://github.com/OpenVPN/openvpn/issues/568)). Also, add unit test.
1837
* Http-proxy: fix bug preventing proxy credentials caching (trac #1187)
c14e58 Samuli Seppänen 2025-02-11 07:05:53 1838
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1839
Windows MSI changes since 2.6.11:
1840
* Built against OpenSSL 3.3.1
1841
* Included openvpn-gui updated to 11.50.0.0
1842
* Update Italian language (github [#696](https://github.com/OpenVPN/openvpn-gui/pull/696))
c14e58 Samuli Seppänen 2025-02-11 07:05:53 1843
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1844
| | | |
1845
|-|-|-|
1846
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.12-I001-amd64.msi.asc)|[OpenVPN-2.6.12-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.12-I001-amd64.msi)|
1847
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.12-I001-arm64.msi.asc)|[OpenVPN-2.6.12-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.12-I001-arm64.msi)|
1848
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.12-I001-x86.msi.asc)|[OpenVPN-2.6.12-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.12-I001-x86.msi)|
1849
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.12.tar.gz.asc)|[openvpn-2.6.12.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.12.tar.gz)|
c14e58 Samuli Seppänen 2025-02-11 07:05:53 1850
1851
For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
1852
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1853
## OpenVPN 2.6.11 -- Released 20 June 2024
c14e58 Samuli Seppänen 2025-02-11 07:05:53 1854
The OpenVPN community project team is proud to release OpenVPN 2.6.11. This is a bugfix release containing several security fixes.
1855
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1856
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.11/Changes.rst)
1857
1858
Security fixes:
1859
021418 novaflash 2025-07-02 12:28:58 1860
* [CVE-2024-4877](https://www.cve.org/CVERecord?id=CVE-2024-4877): Windows: harden interactive service pipe.
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1861
Security scope: a malicious process with "some" elevated privileges
1862
(!SeImpersonatePrivilege) could open the pipe a second time, tricking
1863
openvn GUI into providing user credentials (tokens), getting full
1864
access to the account openvpn-gui.exe runs as.
1865
(Zeze with TeamT5)
021418 novaflash 2025-07-02 12:28:58 1866
* [CVE-2024-5594](https://www.cve.org/CVERecord?id=CVE-2024-5594): control channel: refuse control channel messages with
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1867
nonprintable characters in them. Security scope: a malicious openvpn
1868
peer can send garbage to openvpn log, or cause high CPU load.
1869
(Reynir Björnsson)
021418 novaflash 2025-07-02 12:28:58 1870
* [CVE-2024-28882](https://www.cve.org/CVERecord?id=CVE-2024-28882): only call schedule_exit() once (on a given peer).
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1871
Security scope: an authenticated client can make the server "keep the
1872
session" even when the server has been told to disconnect this client
1873
(Reynir Björnsson)
1874
1875
1876
New features:
1877
1878
* Windows Crypto-API: Implement Windows CA template match for searching
1879
certificates in windows crypto store.
1880
* Support pre-created DCO interface on FreeBSD (OpenVPN would fail to
1881
set ifmode p2p/subnet otherwise)
1882
1883
Bug fixes:
1884
1885
* Fix connect timeout when using SOCKS proxies (trac #328, github [#267](https://github.com/OpenVPN/openvpn/issues/267))
1886
* Work around LibreSSL crashing on OpenBSD 7.5 when enumerating ciphers
1887
(LibreSSL bug, already fixed upstream, but not backported to OpenBSD 7.5,
1888
see also [LibreSSL/OpenBSD#150](https://github.com/libressl/openbsd/issues/150))
1889
* Add bracket in fingerprint message and do not warn about missing
1890
verification (github [#516](https://github.com/OpenVPN/openvpn/issues/516))
1891
1892
Documentation:
1893
1894
* Remove "experimental" denotation for --fast-io
1895
* Correctly document ifconfig_* variables passed to scripts
1896
* Documentation: make section levels consistent
1897
* Samples: Update sample configurations (remove compression & old cipher settings, add more informative comments)
1898
1899
Windows MSI changes since 2.6.10:
1900
* For the Windows-specific security fixes see above
1901
* Built against OpenSSL 3.3.1
1902
* Included openvpn-gui updated to 11.49.0.0
021418 novaflash 2025-07-02 12:28:58 1903
* Contains part of the fix for [CVE-2024-4877](https://www.cve.org/CVERecord?id=CVE-2024-4877)
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1904
1905
Note: Windows MSI was updated to I002 on June 26th. Changes in I002:
1906
* Group names are localized in some localizations, so we have to use SIDs. (Github: [#671](https://github.com/OpenVPN/openvpn-build/issues/671))
1907
1908
| | | |
1909
|-|-|-|
1910
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.11-I002-amd64.msi.asc)|[OpenVPN-2.6.11-I002-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.11-I002-amd64.msi)|
1911
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.11-I002-arm64.msi.asc)|[OpenVPN-2.6.11-I002-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.11-I002-arm64.msi)|
1912
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.11-I002-x86.msi.asc)|[OpenVPN-2.6.11-I002-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.11-I002-x86.msi)|
1913
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.11.tar.gz.asc)|[openvpn-2.6.11.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.11.tar.gz)|
c14e58 Samuli Seppänen 2025-02-11 07:05:53 1914
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1915
For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
c14e58 Samuli Seppänen 2025-02-11 07:05:53 1916
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1917
## OpenVPN 2.5.10 -- Released 21 March 2024
c14e58 Samuli Seppänen 2025-02-11 07:05:53 1918
The OpenVPN community project team is proud to release OpenVPN 2.5.10. This is a bugfix release containing several security fixes specific to the Windows platform.
1919
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1920
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.5.10/Changes.rst)
1921
1922
Note that OpenVPN 2.5.x is in "Old Stable Support" status (see SupportedVersions). This usually means that we do not provide updated Windows Installers anymore, even for security fixes. Since this release fixes several issues specific to the Windows platform we decided to provide installers anyway. This does not change the support status of 2.5.x branch. We might not provide security updates for issues found in the future. We recommend that everyone switch to the 2.6.x versions of installers as soon as possible.
1923
1924
Security fixes:
1925
021418 novaflash 2025-07-02 12:28:58 1926
* [CVE-2024-27459](https://www.cve.org/CVERecord?id=CVE-2024-27459): Windows: fix a possible stack overflow in the
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1927
interactive service component which might lead to a local privilege
1928
escalation.
1929
Reported-by: Vladimir Tokarev <vtokarev@microsoft.com>
021418 novaflash 2025-07-02 12:28:58 1930
* [CVE-2024-24974](https://www.cve.org/CVERecord?id=CVE-2024-24974): Windows: disallow access to the interactive service
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1931
pipe from remote computers.
1932
Reported-by: Vladimir Tokarev <vtokarev@microsoft.com>
021418 novaflash 2025-07-02 12:28:58 1933
* [CVE-2024-27903](https://www.cve.org/CVERecord?id=CVE-2024-27903): Windows: disallow loading of plugins from untrusted
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1934
installation paths, which could be used to attack `openvpn.exe` via
1935
a malicious plugin. Plugins can now only be loaded from the OpenVPN
1936
install directory, the Windows system directory, and possibly from
1937
a directory specified by `HKLM\SOFTWARE\OpenVPN\plugin_dir`.
1938
Reported-by: Vladimir Tokarev <vtokarev@microsoft.com>
021418 novaflash 2025-07-02 12:28:58 1939
* [CVE-2024-1305](https://www.cve.org/CVERecord?id=CVE-2024-1305): Windows TAP driver: Fix potential integer overflow in !TapSharedSendPacket.
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1940
Reported-by: Vladimir Tokarev <vtokarev@microsoft.com>
1941
1942
Windows MSI changes since 2.5.10:
1943
* For the Windows-specific security fixes see above
1944
* Built against OpenSSL 1.1.1w
1945
* Note that OpenSSL 1.1.1 is not supported anymore, so this might not address all known issues in OpenSSL 1.1.1. If that concerns you, please switch to OpenVPN 2.6.x
1946
* Included tap6-windows driver updated to 9.27.0
1947
* Security fix, see above
1948
1949
| | | |
1950
|-|-|-|
1951
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.10-I601-amd64.msi.asc)|[OpenVPN-2.5.10-I601-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.10-I601-amd64.msi)|
1952
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.10-I601-arm64.msi.asc)|[OpenVPN-2.5.10-I601-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.10-I601-arm64.msi)|
1953
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.10-I601-x86.msi.asc)|[OpenVPN-2.5.10-I601-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.10-I601-x86.msi)|
1954
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.5.10.tar.gz.asc)|[openvpn-2.5.10.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.5.10.tar.gz)|
1955
1956
## OpenVPN 2.6.10 -- Released 20 March 2024
c14e58 Samuli Seppänen 2025-02-11 07:05:53 1957
The OpenVPN community project team is proud to release OpenVPN 2.6.10. This is a bugfix release containing several security fixes specific to the Windows platform.
1958
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1959
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.10/Changes.rst)
c14e58 Samuli Seppänen 2025-02-11 07:05:53 1960
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1961
Security fixes:
c14e58 Samuli Seppänen 2025-02-11 07:05:53 1962
021418 novaflash 2025-07-02 12:28:58 1963
* [CVE-2024-27459](https://www.cve.org/CVERecord?id=CVE-2024-27459): Windows: fix a possible stack overflow in the
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1964
interactive service component which might lead to a local privilege
1965
escalation.
1966
Reported-by: Vladimir Tokarev <vtokarev@microsoft.com>
021418 novaflash 2025-07-02 12:28:58 1967
* [CVE-2024-24974](https://www.cve.org/CVERecord?id=CVE-2024-24974): Windows: disallow access to the interactive service
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1968
pipe from remote computers.
1969
Reported-by: Vladimir Tokarev <vtokarev@microsoft.com>
021418 novaflash 2025-07-02 12:28:58 1970
* [CVE-2024-27903](https://www.cve.org/CVERecord?id=CVE-2024-27903): Windows: disallow loading of plugins from untrusted
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1971
installation paths, which could be used to attack `openvpn.exe` via
1972
a malicious plugin. Plugins can now only be loaded from the OpenVPN
1973
install directory, the Windows system directory, and possibly from
1974
a directory specified by `HKLM\SOFTWARE\OpenVPN\plugin_dir`.
1975
Reported-by: Vladimir Tokarev <vtokarev@microsoft.com>
021418 novaflash 2025-07-02 12:28:58 1976
* [CVE-2024-1305](https://www.cve.org/CVERecord?id=CVE-2024-1305): Windows TAP driver: Fix potential integer overflow in !TapSharedSendPacket.
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1977
Reported-by: Vladimir Tokarev <vtokarev@microsoft.com>
c14e58 Samuli Seppänen 2025-02-11 07:05:53 1978
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1979
New features:
c14e58 Samuli Seppänen 2025-02-11 07:05:53 1980
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1981
* `t_client.sh` can now run pre-tests and skip a test block if needed
1982
(e.g. skip NTLM proxy tests if SSL library does not support MD4)
c14e58 Samuli Seppänen 2025-02-11 07:05:53 1983
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1984
User visible changes:
c14e58 Samuli Seppänen 2025-02-11 07:05:53 1985
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1986
* Update copyright notices to 2024
c14e58 Samuli Seppänen 2025-02-11 07:05:53 1987
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1988
Bug fixes:
c14e58 Samuli Seppänen 2025-02-11 07:05:53 1989
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1990
* Windows: if the win-dco driver is used (default) and the GUI requests
1991
use of a proxy server, the connection would fail. Disable DCO in
1992
this case. (Github: [#522](https://github.com/OpenVPN/openvpn/issues/522))
1993
* Compression: minor bugfix in checking option consistency vs. compiled-in
1994
algorithm support
1995
* systemd unit files: remove obsolete syslog.target
c14e58 Samuli Seppänen 2025-02-11 07:05:53 1996
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1997
Documentation:
c14e58 Samuli Seppänen 2025-02-11 07:05:53 1998
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 1999
* remove license warnings about mbedTLS linking (README.mbedtls)
2000
* update documentation references in systemd unit files
2001
* sample config files: remove obsolete tls-*.conf files
2002
* document that auth-user-pass may be inlined
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2003
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2004
Windows MSI changes since 2.6.9:
2005
* For the Windows-specific security fixes see above
2006
* Built against OpenSSL 3.2.1
2007
* Included tap6-windows driver updated to 9.27.0
2008
* Security fix, see above
2009
* Included ovpn-dco-win driver updated to 1.0.1
2010
* Ensure we don't pass too large key size to CryptoNG. We do not consider this a security issue since the CryptoNG API handles this gracefully either way.
2011
* Included openvpn-gui updated to 11.48.0.0
2012
* Position tray tooltip above the taskbar
2013
* Combine title and message in tray icon tip text
2014
* Use a custom tooltip window for the tray icon
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2015
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2016
Note: Windows MSI was updated to I002 on April 15th. Changes in I002:
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2017
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2018
* Update include ovpn-dco-win to v1.1.1
2019
* Improves reconnect behavior after hibernate/standby. (Github: [#64](https://github.com/OpenVPN/ovpn-dco-win/issues/64))
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2020
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2021
Note: Windows MSI was updated to I003 on May 23rd. Changes in I003:
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2022
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2023
* Update include ovpn-dco-win to v1.2.1
2024
* Fix bug check in timer management routines. (Github: [#70](https://github.com/OpenVPN/ovpn-dco-win/issues/70))
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2025
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2026
| | | |
2027
|-|-|-|
2028
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.10-I003-amd64.msi.asc)|[OpenVPN-2.6.10-I003-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.10-I003-amd64.msi)|
2029
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.10-I003-arm64.msi.asc)|[OpenVPN-2.6.10-I003-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.10-I003-arm64.msi)|
2030
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.10-I003-x86.msi.asc)|[OpenVPN-2.6.10-I003-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.10-I003-x86.msi)|
2031
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.10.tar.gz.asc)|[openvpn-2.6.10.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.10.tar.gz)|
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2032
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2033
For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2034
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2035
## OpenVPN 2.6.9 -- Released 12 February 2024
2036
The OpenVPN community project team is proud to release OpenVPN 2.6.9. This is a bugfix release containing one security fix for the Windows installer.
2037
2038
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.9/Changes.rst)
2039
2040
Security fixes:
2041
021418 novaflash 2025-07-02 12:28:58 2042
* Windows Installer: fix [CVE-2023-7235](https://www.cve.org/CVERecord?id=CVE-2023-7235) where installing to a non-default
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2043
directory could lead to a local privilege escalation. Reported by Will Dormann.
2044
2045
New features:
2046
2047
* Add support for building with mbedTLS 3.x.x
2048
* New option `--force-tls-key-material-export` to only accept clients
2049
that can do TLS keying material export to generate session keys
2050
(mostly an internal option to better deal with TLS 1.0 PRF failures).
2051
* Windows: bump vcpkg-ports/pkcs11-helper to 1.30
2052
* Log incoming SSL alerts in easier to understand form and move logging
2053
from `--verb 8` to `--verb 3`.
2054
* protocol_dump(): add support for printing `--tls-crypt` packets
2055
2056
User visible changes:
2057
2058
* License change is now complete, and all code has been re-licensed
2059
under the new license (still GPLv2, but with new linking exception
2060
for Apache2 licensed code). See [COPYING](https://github.com/OpenVPN/openvpn/blob/release/2.6/COPYING) for details.
2061
2062
Code that could not be re-licensed has been removed or rewritten.
2063
* The original code for the `--tls-export-cert` feature has been removed
2064
(due to the re-licensing effort) and rewritten without looking at the
2065
original code. Feature-compatibility has been tested by other developers,
2066
looking at both old and new code and documentation, so there *should*
2067
not be a user-visible change here.
2068
* IPv6 route addition/deletion are now logged on the same level (3) as
2069
for IPv4. Previously IPv6 was always logged at `--verb 1`.
2070
* Better handling of TLS 1.0 PRF failures in the underlying SSL library
2071
(e.g. on some FIPS builds) - this is now reported on startup, and
2072
clients before 2.6.0 that can not use TLS EKM to generate key material
2073
are rejected by the server. Also, error messages are improved to see
2074
what exactly failed.
2075
2076
Notable bug fixes:
2077
2078
* FreeBSD: for servers with multiple clients, reporting of peer traffic
2079
statistics would fail due to insufficient buffer space (Github: [#487](https://github.com/OpenVPN/openvpn/issues/487))
2080
2081
Windows MSI changes since 2.6.8:
2082
* Security fix, see above
2083
* Built against OpenSSL 3.2.0
2084
* Included openvpn-gui updated to 11.47.0.0
2085
* Windows GUI: always update tray icon on state change (Github: [#669](https://github.com/OpenVPN/openvpn-gui/issues/669))
2086
(for persistent connection profiles, "connecting" state would not show)
2087
2088
| | | |
2089
|-|-|-|
2090
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.9-I001-amd64.msi.asc)|[OpenVPN-2.6.9-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.9-I001-amd64.msi)|
2091
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.9-I001-arm64.msi.asc)|[OpenVPN-2.6.9-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.9-I001-arm64.msi)|
2092
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.9-I001-x86.msi.asc)|[OpenVPN-2.6.9-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.9-I001-x86.msi)|
2093
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.9.tar.gz.asc)|[openvpn-2.6.9.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.9.tar.gz)|
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2094
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2095
For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2096
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2097
## OpenVPN 2.6.8 -- Released 17 November 2023
2098
The OpenVPN community project team is proud to release OpenVPN 2.6.8. This is a small bugfix release fixing a few regressions in 2.6.7 release.
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2099
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2100
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.8/Changes.rst)
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2101
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2102
User visible changes:
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2103
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2104
* Windows: print warning if pushed options require DHCP (e.g. DOMAIN-SEARCH)
2105
and driver in use does not use DHCP (wintun, dco).
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2106
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2107
Bug fixes:
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2108
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2109
* SIGSEGV crash: Do not check key_state buffers that are in S_UNDEF state
2110
(Github [#449](https://github.com/OpenVPN/openvpn/issues/449)) - the new sanity check function introduced in 2.6.7
2111
sometimes tried to use a NULL pointer after an unsuccessful TLS handshake
2112
* Windows: `--dns` option did not work when tap-windows6 driver was used,
2113
because internal flag for "apply DNS option to DHCP server" wasn't set
2114
(Github [#447](https://github.com/OpenVPN/openvpn/issues/447))
2115
* Windows: fix status/log file permissions, caused by regression after
2116
changing to CMake build system (Github: [#454](https://github.com/OpenVPN/openvpn/issues/454), Trac: [#1430](https://community.openvpn.net/openvpn/ticket/1430))
2117
* Windows: fix `--chdir` failures, also caused by error in CMake build system
2118
(Github [#448](https://github.com/OpenVPN/openvpn/issues/448))
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2119
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2120
Windows MSI changes since 2.6.7:
2121
* Included openvpn-gui updated to 11.46.0.0
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2122
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2123
| | | |
2124
|-|-|-|
2125
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.8-I001-amd64.msi.asc)|[OpenVPN-2.6.8-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.8-I001-amd64.msi)|
2126
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.8-I001-arm64.msi.asc)|[OpenVPN-2.6.8-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.8-I001-arm64.msi)|
2127
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.8-I001-x86.msi.asc)|[OpenVPN-2.6.8-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.8-I001-x86.msi)|
2128
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.8.tar.gz.asc)|[openvpn-2.6.8.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.8.tar.gz)|
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2129
2130
For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
2131
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2132
## OpenVPN 2.6.7 -- Released 09 November 2023
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2133
The OpenVPN community project team is proud to release OpenVPN 2.6.7. This is a bugfix release containing security fixes.
2134
2135
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.7/Changes.rst)
2136
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2137
Security Fixes:
2138
021418 novaflash 2025-07-02 12:28:58 2139
* [CVE-2023-46850](https://www.cve.org/CVERecord?id=CVE-2023-46850) OpenVPN versions between 2.6.0 and 2.6.6 incorrectly use a send buffer after it has been free()d in some circumstances, causing some free()d memory to be sent to the peer. All configurations using TLS (e.g. not using --secret) are affected by this issue. (found while tracking down CVE-2023-46849 / Github [#400](https://github.com/OpenVPN/openvpn/issues/400), [#417](https://github.com/OpenVPN/openvpn/issues/417))
2140
* [CVE-2023-46849](https://www.cve.org/CVERecord?id=CVE-2023-46849) OpenVPN versions between 2.6.0 and 2.6.6 incorrectly restore `--fragment` configuration in some circumstances, leading to a division by zero when `--fragment` is used. On platforms where division by zero is fatal, this will cause an OpenVPN crash.
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2141
(Github [#400](https://github.com/OpenVPN/openvpn/issues/400), [#417](https://github.com/OpenVPN/openvpn/issues/417)).
2142
2143
User visible changes:
2144
2145
* DCO: warn if DATA_V1 packets are sent by the other side - this a hard
2146
incompatibility between a 2.6.x client connecting to a 2.4.0-2.4.4 server,
2147
and the only fix is to use `--disable-dco`.
2148
* Remove OpenSSL Engine method for loading a key. This had to be removed
2149
because the original author did not agree to relicensing the code with
2150
the new linking exception added. This was a somewhat obsolete feature
2151
anyway as it only worked with OpenSSL 1.x, which is end-of-support.
2152
* add warning if p2p NCP client connects to a p2mp server - this is a
2153
combination that used to work without cipher negotiation (pre 2.6 on
2154
both ends), but would fail in non-obvious ways with 2.6 to 2.6.
2155
* add warning to `--show-groups` that not all supported groups are listed
2156
(this is due the internal enumeration in OpenSSL being a bit weird,
2157
omitting X448 and X25519 curves).
2158
* `--dns`: remove support for `exclude-domains` argument
2159
(this was a new 2.6 option, with no backend support implemented yet
2160
on any platform, and it turns out that no platform supported it at all -
2161
so remove option again)
2162
* warn user if INFO control message too long, do not forward to management
2163
client (safeguard against protocol-violating server implementations)
2164
2165
New features:
2166
2167
* DCO-WIN: get and log driver version (for easier debugging).
2168
* print "peer temporary key details" in TLS handshake
2169
* log OpenSSL errors on failure to set certificate, for example if the
2170
algorithms used are in acceptable to OpenSSL (misleading message would
2171
be printed in cryptoapi / pkcs11 scenarios)
2172
* add CMake build system for MinGW and MSVC builds
2173
* remove old MSVC build system
2174
* improve cmocka unit test building for Windows
2175
2176
Windows MSI changes since 2.6.6:
2177
* Included openvpn-gui updated to 11.45.0.0
2178
* Add clarity for error on missing management parameter.
2179
See GH [#657](https://github.com/OpenVPN/openvpn-gui/issues/657)
2180
* Improve "OpenVPN GUI" tooltip handling
2181
See GH [#649](https://github.com/OpenVPN/openvpn-gui/issues/649)
2182
* MSIs now use OpenSSL 3.1.4
2183
2184
| | | |
2185
|-|-|-|
2186
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.7-I001-amd64.msi.asc)|[OpenVPN-2.6.7-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.7-I001-amd64.msi)|
2187
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.7-I001-arm64.msi.asc)|[OpenVPN-2.6.7-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.7-I001-arm64.msi)|
2188
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.7-I001-x86.msi.asc)|[OpenVPN-2.6.7-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.7-I001-x86.msi)|
2189
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.7.tar.gz.asc)|[openvpn-2.6.7.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.7.tar.gz)|
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2190
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2191
For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2192
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2193
## OpenVPN 2.6.6 -- Released 15 August 2023
2194
The OpenVPN community project team is proud to release OpenVPN 2.6.6. This is a small bugfix release.
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2195
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2196
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.6/Changes.rst)
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2197
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2198
User visible changes:
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2199
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2200
* OCC exit messages are now logged more visibly
2201
See GH [#391](https://github.com/OpenVPN/openvpn/issues/391).
2202
* OpenSSL error messages are now logged with more details (for example,
2203
when loading a provider fails, which .so was tried, and why did it fail)
2204
See GH [#361](https://github.com/OpenVPN/openvpn/issues/361).
2205
* print a more user-friendly message when tls-crypt-v2 client auth fails
2206
* packaging now includes all documentation in the source tarball
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2207
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2208
New features:
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2209
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2210
* set WINS server via interactive service - this adds support for
2211
"dhcp-option WINS 192.0.2.1" for DCO + wintun interfaces where no
2212
DHCP server is used.
2213
See GH [#373](https://github.com/OpenVPN/openvpn/issues/373).
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2214
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2215
Windows MSI changes since 2.6.5:
2216
* Included openvpn-gui updated to 11.44.0.0
2217
* MSIs now use OpenSSL 3.1.2
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2218
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2219
| | | |
2220
|-|-|-|
2221
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.6-I001-amd64.msi.asc)|[OpenVPN-2.6.6-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.6-I001-amd64.msi)|
2222
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.6-I001-arm64.msi.asc)|[OpenVPN-2.6.6-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.6-I001-arm64.msi)|
2223
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.6-I001-x86.msi.asc)|[OpenVPN-2.6.6-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.6-I001-x86.msi)|
2224
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.6.tar.gz.asc)|[openvpn-2.6.6.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.6.tar.gz)|
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2225
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2226
For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2227
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2228
## OpenVPN 2.6.5 -- Released 13 June 2023
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2229
The OpenVPN community project team is proud to release OpenVPN 2.6.5. This is a small bugfix release.
2230
2231
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.5/Changes.rst)
2232
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2233
User visible changes:
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2234
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2235
* tapctl (windows): generate driver-specific names (if using tapctl to
2236
create additional tap/wintun/dco devices, and not using --name).
2237
See GH [#337](https://github.com/OpenVPN/openvpn/issues/337).
2238
* interactive service (windows): do not force target desktop for
2239
openvpn.exe - this has no impact for normal use, but enables running
2240
of OpenVPN in a scripted way when no user is logged on (for example,
2241
via task scheduler).
2242
See GH [openvpn-gui#626](https://github.com/OpenVPN/openvpn-gui/issues/626)
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2243
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2244
Windows MSI changes since 2.6.4:
2245
* MSIs now use OpenSSL 3.1.1
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2246
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2247
Debian/Ubuntu packages in OpenvpnSoftwareRepos are now available for arm64.
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2248
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2249
| | | |
2250
|-|-|-|
2251
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.5-I001-amd64.msi.asc)|[OpenVPN-2.6.5-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.5-I001-amd64.msi)|
2252
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.5-I001-arm64.msi.asc)|[OpenVPN-2.6.5-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.5-I001-arm64.msi)|
2253
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.5-I001-x86.msi.asc)|[OpenVPN-2.6.5-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.5-I001-x86.msi)|
2254
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.5.tar.gz.asc)|[openvpn-2.6.5.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.5.tar.gz)|
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2255
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2256
For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2257
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2258
## OpenVPN 2.6.4 -- Released 11 May 2023
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2259
The OpenVPN community project team is proud to release OpenVPN 2.6.4. This is a small bugfix release.
2260
2261
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.4/Changes.rst)
2262
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2263
Note:
2264
* **License amendment**: all **new** commits fall under a modified license that
2265
explicitly permits linking with Apache2 libraries (mbedTLS, OpenSSL) -
2266
see COPYING for details. Existing code will fall under the new license
2267
as soon as all contributors have agreed to the change - work ongoing.
2268
2269
Feature changes:
2270
* DCO: support kernel-triggered key rotation (avoid IV reuse after 2^32^
2271
packets). This is the userland side, accepting a message from kernel,
2272
and initiating a TLS renegotiation. As of 2.6.4 release, only implemented in
2273
FreeBSD kernel.
2274
2275
Windows MSI changes since 2.6.3:
2276
* Rebuilt included tap-windows driver with the correct version of the old Windows 7 driver, removing a warning about unsigned driver on Windows 7 installation.
2277
See GH [openvpn-build#365](https://github.com/OpenVPN/openvpn-build/issues/365).
2278
2279
| | | |
2280
|-|-|-|
2281
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.4-I001-amd64.msi.asc)|[OpenVPN-2.6.4-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.4-I001-amd64.msi)|
2282
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.4-I001-arm64.msi.asc)|[OpenVPN-2.6.4-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.4-I001-arm64.msi)|
2283
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.4-I001-x86.msi.asc)|[OpenVPN-2.6.4-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.4-I001-x86.msi)|
2284
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.4.tar.gz.asc)|[openvpn-2.6.4.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.4.tar.gz)|
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2285
2286
For Community-maintained packages for Linux distributions see OpenvpnSoftwareRepos
2287
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2288
## OpenVPN 2.6.3 -- Released 13 April 2023
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2289
The OpenVPN community project team is proud to release OpenVPN 2.6.3. This is a small bugfix release.
2290
2291
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.3/Changes.rst)
2292
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2293
Feature changes:
2294
* Windows: support setting DNS domain in configurations without GUI and DHCP (typically wintun or windco drivers), see GH [openvpn#306](https://github.com/OpenVPN/openvpn/issues/306).
2295
2296
Windows MSI changes since 2.6.2:
2297
* Several Windows-specific issues fixed:
2298
* ensure interactive service stays enabled after silent reinstall, see GH [openvpn-build#348](https://github.com/OpenVPN/openvpn-build/issues/348), [openvpn-build#349](https://github.com/OpenVPN/openvpn-build/issues/349) and [openvpn-build#351](https://github.com/OpenVPN/openvpn-build/issues/351)
2299
* repair querying install path info for easyrsa-start.bat on some Windows language versions, see GH [openvpn-build#352](https://github.com/OpenVPN/openvpn-build/issues/352).
2300
* MSIs are now built against OpenSSL 3.1.0.
2301
* Update included openvpn-gui to 11.41.0.0
2302
* This update removes the ability to change the password of a private key from the GUI. This was a niche feature which caused a direct dependency of
2303
GUI on OpenSSL. Use openssl.exe directly if you need to edit a private key.
2304
2305
Note: Windows MSI was updated to I002 on April 26th. Changes in I002:
2306
* The GPG subkey for creating the .asc files for the downloads has been updated. You might need to re-download or update the GPG key if verifying the signatures.
2307
* Fix the encoding of some documentation/sample files included in the installer. See GH [openvpn-build#358](https://github.com/OpenVPN/openvpn-build/issues/358)
2308
* Update include tap-windows6 driver to 9.25.0
2309
* Fixes a problem with sending small non-IP packets (e.g. PPPoE) over the VPN connection. See GH [tap-windows6#158](https://github.com/OpenVPN/tap-windows6/issues/158)
2310
* Fixes occasional TCP performance degradation on Windows Server 2022 See GH [tap-windows6#147](https://github.com/OpenVPN/tap-windows6/pull/147)
2311
* Note: The new driver is only used on Windows 10 and newer. We can't rebuild drivers for Windows 7/8 since Microsoft doesn't support the signing mechanism anymore. We include the previous driver version to still allow installation on Windows 7/8.
2312
* Update included openvpn-gui to 11.42.0.0
2313
* Fixes a problem with passphrase prompt was sometimes not displayed. See GH [openvpn-gui#619](https://github.com/OpenVPN/openvpn-gui/issues/619)
2314
* Adds "Password Reveal" feature which allows you to see passwords while entering them.
2315
2316
Note: Windows MSI was updated to I003 on April 27th. Changes in I003:
2317
* Update include tap-windows6 driver to 9.26.0
2318
* Revert fix for occasional TCP performance degradation on Windows Server 2022 (GH [tap-windows6#147](https://github.com/OpenVPN/tap-windows6/pull/147)) since users reported BSODs in some (undetermined) scenarios.
2319
2320
| | | |
2321
|-|-|-|
2322
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.3-I003-amd64.msi.asc)|[OpenVPN-2.6.3-I003-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.3-I003-amd64.msi)|
2323
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.3-I003-arm64.msi.asc)|[OpenVPN-2.6.3-I003-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.3-I003-arm64.msi)|
2324
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.3-I003-x86.msi.asc)|[OpenVPN-2.6.3-I003-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.3-I003-x86.msi)|
2325
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.3.tar.gz.asc)|[openvpn-2.6.3.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.3.tar.gz)|
2326
2327
## OpenVPN 2.6.2 -- Released 24 March 2023
2328
The OpenVPN community project team is proud to release OpenVPN 2.6.2. This is mostly a bugfix release with some improvements.
2329
2330
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.2/Changes.rst)
2331
2332
Feature changes:
2333
* implement byte counter statistics for DCO Linux (p2mp server and client)
2334
* implement byte counter statistics for DCO Windows (client only)
2335
* `--dns server <n> address ...` now permits up to 8 v4 or v6 addresses
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2336
2337
**Important note for Linux DCO users**:
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2338
* New control packets flow for data channel offloading on Linux:
2339
2.6.2+ changes the way OpenVPN control packets are handled on
2340
Linux when DCO is active, fixing the lockups observed with 2.6.0/2.6.1
2341
under high client connect/disconnect activity.
2342
This is an **INCOMPATIBLE** change and therefore an ovpn-dco kernel
2343
module older than v0.2.20230323 (commit ID 726fdfe0fa21) will not
2344
work anymore and must be upgraded. The kernel module was renamed to
2345
"ovpn-dco-v2.ko" in order to highlight this change and ensure that
2346
users and userspace software could easily understand which version
2347
is loaded. Attempting to use the old ovpn-dco with 2.6.2+ will
2348
lead to disabling DCO at runtime.
2349
2350
Windows MSI changes since 2.6.1:
2351
* Update included openvpn-gui to 11.39.0.0
2352
2353
| | | |
2354
|-|-|-|
2355
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.2-I001-amd64.msi.asc)|[OpenVPN-2.6.2-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.2-I001-amd64.msi)|
2356
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.2-I001-arm64.msi.asc)|[OpenVPN-2.6.2-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.2-I001-arm64.msi)|
2357
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.2-I001-x86.msi.asc)|[OpenVPN-2.6.2-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.2-I001-x86.msi)|
2358
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.2.tar.gz.asc)|[openvpn-2.6.2.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.2.tar.gz)|
2359
2360
## OpenVPN 2.6.1 -- Released 8 March 2023
2361
The OpenVPN community project team is proud to release OpenVPN 2.6.1. This is mostly a bugfix release with some improvements.
2362
2363
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.1/Changes.rst)
2364
2365
Feature changes:
2366
* Dynamic TLS Crypt:
2367
When both peers are OpenVPN 2.6.1+, OpenVPN will dynamically create
2368
a tls-crypt key that is used for renegotiation. This ensure that only the
2369
previously authenticated peer can do trigger renegotiation and complete
2370
renegotiations.
2371
* CryptoAPI (Windows): support issuer name as a selector.
2372
Certificate selection string can now specify a partial
2373
issuer name string as "--cryptoapicert ISSUER:<string>" where
2374
<string> is matched as a substring of the issuer (CA) name in
2375
the certificate.
2376
2377
Note: configure now enables DCO build by default on FreeBSD and Linux. On Linux
2378
this brings in a new default dependency for libnl-genl (for Linux distributions
2379
that are too old to have a suitable version of the library, use "configure --disable-dco")
2380
2381
Windows MSI changes since 2.6.0:
2382
* Update included ovpn-dco-win driver to 0.9.2
2383
2384
| | | |
2385
|-|-|-|
2386
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.1-I001-amd64.msi.asc)|[OpenVPN-2.6.1-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.1-I001-amd64.msi)|
2387
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.1-I001-arm64.msi.asc)|[OpenVPN-2.6.1-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.1-I001-arm64.msi)|
2388
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.1-I001-x86.msi.asc)|[OpenVPN-2.6.1-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.1-I001-x86.msi)|
2389
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.1.tar.gz.asc)|[openvpn-2.6.1.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.1.tar.gz)|
2390
2391
## OpenVPN 2.5.9 -- Released 15 February 2023
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2392
The OpenVPN community project team is proud to release OpenVPN 2.5.9. This is a small bugfix release.
2393
2394
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.5.9/Changes.rst)
2395
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2396
Windows MSI changes since 2.5.8:
2397
* Build against OpenSSL 1.1.1t which contains several security fixes.
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2398
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2399
| | | |
2400
|-|-|-|
2401
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.9-I601-amd64.msi.asc)|[OpenVPN-2.5.9-I601-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.9-I601-amd64.msi)|
2402
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.9-I601-arm64.msi.asc)|[OpenVPN-2.5.9-I601-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.9-I601-arm64.msi)|
2403
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.9-I601-x86.msi.asc)|[OpenVPN-2.5.9-I601-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.5.9-I601-x86.msi)|
2404
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.5.9.tar.gz.asc)|[openvpn-2.5.9.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.5.9.tar.gz)|
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2405
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2406
## OpenVPN 2.6.0 -- Released 25 January 2023
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2407
The OpenVPN community project team is proud to release OpenVPN 2.6.0. This is a release with some major new features.
2408
2409
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.0/Changes.rst)
2410
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2411
Changes since RC2:
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2412
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2413
* Various bugfixes, see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.0/Changes.rst)
2414
2415
Windows MSI changes since RC2:
2416
* Included openvpn-gui updated to 11.37.0.0. See [CHANGES.rst](https://github.com/OpenVPN/openvpn-gui/blob/v11.37.0.0/CHANGES.rst).
2417
* DCO driver is now included as a installer module (msm) so that other products (like OpenVPN Connect) can share the DCO installation.
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2418
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2419
Note: Windows MSI was updated to I003 on January 26th. Changes in I003:
2420
* Fix installation on Windows 7
2421
* Fix broken tray icon menu with single profile (regression in openvpn-gui 11.36.0)
2422
2423
Note: Windows MSI was updated to I004 on February 6th. Changes in I004:
2424
* Update included ovpn-dco-win driver to 0.9.0. Fixes an issue that breaks Windows boot on some machines. See [OpenVPN/ovpn-dco-win#24](https://github.com/OpenVPN/ovpn-dco-win/issues/24).
2425
* Update included easy-rsa to 3.1.2
2426
2427
Note: Windows MSI was updated to I005 on February 15th. Changes in I005:
2428
* Update included ovpn-dco-win driver to 0.9.1.
2429
* Fixes an potential crash on machines that use "legacy standby" (S3). See [OpenVPN/ovpn-dco-win#36](https://github.com/OpenVPN/ovpn-dco-win/issues/36).
2430
* Fixes an incompatibility of DCO driver with Citrix DNE Lightweight Filter. See [OpenVPN/ovpn-dco-win#31](https://github.com/OpenVPN/ovpn-dco-win/issues/31).
2431
* Built against OpenSSL 3.0.8 which includes several security fixes.
2432
2433
New features and improvements in 2.6.0 compared to 2.5.8:
2434
2435
* Data Channel Offload (DCO) kernel acceleration support for Windows, Linux, and FreeBSD.
2436
* OpenSSL 3 support, which is now the default on Windows.
2437
* Improved handling of tunnel MTU, including support for pushable MTU.
2438
* Outdated cryptographic algorithms disabled by default, but there are options to override if necessary.
2439
* Reworked TLS handshake, making OpenVPN immune to replay-packet state exhaustion attacks.
2440
* Added --peer-fingerprint mode for a more simplistic certificate setup and verification.
2441
* Added Pre-Logon Access Provider support to OpenVPN GUI for Windows.
2442
* Improved protocol negotiation, leading to faster connection setup.
2443
* Updated easy-rsa3 bundled with the installer on Windows.
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2444
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2445
On Windows DCO will be used by default for client connections unless the configuration contains settings that are not DCO compatible, such as compression. DCO support on Linux requires an additional kernel module to be installed, this is available from our [OpenvpnSoftwareRepos software repositories for Linux], and is also available for OpenVPN3 Linux client.
2446
2447
| | | |
2448
|-|-|-|
2449
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.0-I005-amd64.msi.asc)|[OpenVPN-2.6.0-I005-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.0-I005-amd64.msi)|
2450
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.0-I005-arm64.msi.asc)|[OpenVPN-2.6.0-I005-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.0-I005-arm64.msi)|
2451
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.0-I005-x86.msi.asc)|[OpenVPN-2.6.0-I005-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6.0-I005-x86.msi)|
2452
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.0.tar.gz.asc)|[openvpn-2.6.0.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.0.tar.gz)|
2453
2454
## OpenVPN 2.6_rc2 -- Released 12 January 2023
2455
The OpenVPN community project team is proud to release OpenVPN 2.6_rc2. This is a release with some major new features and currently in beta (you can also download the [stable release](https://openvpn.net/community-downloads) should you require it).
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2456
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2457
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6_rc2/Changes.rst)
2458
2459
Changes since RC1:
2460
2461
* add rate limiter for incoming "initial handshake packets", enabled by
2462
default with a limit of 100 packets per 10 seconds. This change makes
2463
OpenVPN servers uninteresting as an UDP reflection DDoS engine.
2464
* report `CONNECTED,ROUTE_ERROR` to management GUI if connection to
2465
server succeeds but not all routes can be installed (Windows and
2466
!Linux/Netlink only, so far)
2467
* Various bugfixes, see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6_rc2/Changes.rst)
2468
2469
Windows MSI changes since RC1:
2470
* Included openvpn-gui updated to 11.35.0.0. See [CHANGES.rst](https://github.com/OpenVPN/openvpn-gui/blob/v11.35.0.0/CHANGES.rst).
2471
* New feature: Support the `CONNECTED,ROUTE_ERROR` management message (see above)
2472
* Fix some issues related to upgrading:
2473
* "Run on logon" option not preserved when updating from 2.5 to 2.6
2474
* Fix check for running service when upgrading from old NSIS installations
2475
2476
Debian packages changes since RC1:
2477
* Packages for Debian bookworm are now available.
2478
2479
New features and improvements in 2.6.0 compared to 2.5.8:
2480
2481
* Data Channel Offload (DCO) kernel acceleration support for Windows, Linux, and FreeBSD.
2482
* OpenSSL 3 support, which is now the default on Windows.
2483
* Improved handling of tunnel MTU, including support for pushable MTU.
2484
* Outdated cryptographic algorithms disabled by default, but there are options to override if necessary.
2485
* Reworked TLS handshake, making OpenVPN immune to replay-packet state exhaustion attacks.
2486
* Added --peer-fingerprint mode for a more simplistic certificate setup and verification.
2487
* Added Pre-Logon Access Provider support to OpenVPN GUI for Windows.
2488
* Improved protocol negotiation, leading to faster connection setup.
2489
* Updated easy-rsa3 bundled with the installer on Windows.
2490
2491
On Windows DCO will be used by default for client connections unless the configuration contains settings that are not DCO compatible, such as compression. DCO support on Linux requires an additional kernel module to be installed, this is available from our [OpenvpnSoftwareRepos software repositories for Linux], and is also available for OpenVPN3 Linux client.
2492
2493
| | | |
2494
|-|-|-|
2495
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc2-I002-amd64.msi.asc)|[OpenVPN-2.6_rc2-I002-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc2-I002-amd64.msi)|
2496
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc2-I002-arm64.msi.asc)|[OpenVPN-2.6_rc2-I002-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc2-I002-arm64.msi)|
2497
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc2-I002-x86.msi.asc)|[OpenVPN-2.6_rc2-I002-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc2-I002-x86.msi)|
2498
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6_rc2.tar.gz.asc)|[openvpn-2.6_rc2.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6_rc2.tar.gz)|
2499
2500
## OpenVPN 2.6_rc1 -- Released 28 December 2022
2501
The OpenVPN community project team is proud to release OpenVPN 2.6_rc1. This is a release with some major new features and currently in beta (you can also download the [stable release](https://openvpn.net/community-downloads) should you require it).
2502
2503
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6_rc1/Changes.rst)
2504
2505
Changes since Beta 2:
2506
2507
* Officially deprecate NTLMv1 proxy auth method in 2.6. Will be removed in 2.7.
2508
* Support unlimited number of connection entries and remote entries.
2509
* New management commands to enumerate and list remote entries.
2510
* Various bugfixes, see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6_rc1/Changes.rst)
2511
2512
Windows MSI changes since Beta 2:
2513
* Included openvpn-gui updated to 11.34.0.0. See [CHANGES.rst](https://github.com/OpenVPN/openvpn-gui/blob/v11.34.0.0/CHANGES.rst).
2514
* New feature: Connections active on exit/logout are now automatically restarted in the next session of the GUI
2515
* Windows installers are now built with Visual Studio 17 2022 (previously built with VS 16 2019)
2516
2517
New features and improvements in 2.6.0 compared to 2.5.8:
2518
2519
* Data Channel Offload (DCO) kernel acceleration support for Windows, Linux, and FreeBSD.
2520
* OpenSSL 3 support, which is now the default on Windows.
2521
* Improved handling of tunnel MTU, including support for pushable MTU.
2522
* Outdated cryptographic algorithms disabled by default, but there are options to override if necessary.
2523
* Reworked TLS handshake, making OpenVPN immune to replay-packet state exhaustion attacks.
2524
* Added --peer-fingerprint mode for a more simplistic certificate setup and verification.
2525
* Added Pre-Logon Access Provider support to OpenVPN GUI for Windows.
2526
* Improved protocol negotiation, leading to faster connection setup.
2527
* Updated easy-rsa3 bundled with the installer on Windows.
2528
2529
On Windows DCO will be used by default for client connections unless the configuration contains settings that are not DCO compatible, such as compression. DCO support on Linux requires an additional kernel module to be installed, this is available from our [OpenvpnSoftwareRepos software repositories for Linux], and is also available for OpenVPN3 Linux client.
2530
2531
| | | |
2532
|-|-|-|
2533
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc1-I001-amd64.msi.asc)|[OpenVPN-2.6_rc1-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc1-I001-amd64.msi)|
2534
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc1-I001-arm64.msi.asc)|[OpenVPN-2.6_rc1-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc1-I001-arm64.msi)|
2535
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc1-I001-x86.msi.asc)|[OpenVPN-2.6_rc1-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_rc1-I001-x86.msi)|
2536
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6_rc1.tar.gz.asc)|[openvpn-2.6_rc1.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6_rc1.tar.gz)|
2537
2538
## OpenVPN 2.6_beta2 -- Released 15 December 2022
2539
The OpenVPN community project team is proud to release OpenVPN 2.6_beta2. This is a release with some major new features and currently in beta (you can also download the [stable release](https://openvpn.net/community-downloads) should you require it).
2540
2541
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6_beta2/Changes.rst)
2542
2543
Changes since Beta 1:
2544
2545
* Transport statistics (bytes in/out) for DCO environments. Currently only for Windows clients and FreeBSD servers. Other platforms will be fixed in next release.
2546
* Various bugfixes, see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6_beta2/Changes.rst)
2547
2548
Windows MSI changes since Beta 1:
2549
* Included openvpn-gui updated to 11.33.0.0. See [CHANGES.rst](https://github.com/OpenVPN/openvpn-gui/blob/v11.33.0.0/CHANGES.rst).
2550
* Update included pkcs11-helper so it can load pkcs11 providers from outside of its own install directory.
2551
* Add legacy provider for included OpenSSL so that the workarounds documented for old ciphers work on Windows.
2552
2553
New features and improvements in 2.6.0 compared to 2.5.8:
2554
2555
* Data Channel Offload (DCO) kernel acceleration support for Windows, Linux, and FreeBSD.
2556
* OpenSSL 3 support, which is now the default on Windows.
2557
* Improved handling of tunnel MTU, including support for pushable MTU.
2558
* Outdated cryptographic algorithms disabled by default, but there are options to override if necessary.
2559
* Reworked TLS handshake, making OpenVPN immune to replay-packet state exhaustion attacks.
2560
* Added --peer-fingerprint mode for a more simplistic certificate setup and verification.
2561
* Added Pre-Logon Access Provider support to OpenVPN GUI for Windows.
2562
* Improved protocol negotiation, leading to faster connection setup.
2563
* Updated easy-rsa3 bundled with the installer on Windows.
2564
2565
On Windows DCO will be used by default for client connections unless the configuration contains settings that are not DCO compatible, such as compression. DCO support on Linux requires an additional kernel module to be installed, this is available from our [OpenvpnSoftwareRepos software repositories for Linux], and is also available for OpenVPN3 Linux client.
2566
2567
| | | |
2568
|-|-|-|
2569
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta2-I001-amd64.msi.asc)|[OpenVPN-2.6_beta2-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta2-I001-amd64.msi)|
2570
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta2-I001-arm64.msi.asc)|[OpenVPN-2.6_beta2-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta2-I001-arm64.msi)|
2571
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta2-I001-x86.msi.asc)|[OpenVPN-2.6_beta2-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta2-I001-x86.msi)|
2572
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6_beta2.tar.gz.asc)|[openvpn-2.6_beta2.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6_beta2.tar.gz)|
2573
2574
## OpenVPN 2.6_beta1 -- Released 2 December 2022
2575
The OpenVPN community project team is proud to release OpenVPN 2.6_beta1. This is a release with some major new features and currently in beta (you may find [stable release](https://openvpn.net/community-downloads) should you require it).
c14e58 Samuli Seppänen 2025-02-11 07:05:53 2576
2577
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6_beta1/Changes.rst)
2578
0f2d41 Samuli Seppänen 2025-02-12 13:37:02 2579
There were a number of new features and improvements:
2580
2581
* Data Channel Offload (DCO) kernel acceleration support for Windows, Linux, and FreeBSD.
2582
* OpenSSL 3 support, which is now the default on Windows.
2583
* Improved handling of tunnel MTU, including support for pushable MTU.
2584
* Outdated cryptographic algorithms disabled by default, but there are options to override if necessary.
2585
* Reworked TLS handshake, making OpenVPN immune to replay-packet state exhaustion attacks.
2586
* Added --peer-fingerprint mode for a more simplistic certificate setup and verification.
2587
* Added Pre-Logon Access Provider support to OpenVPN GUI for Windows.
2588
* Improved protocol negotiation, leading to faster connection setup.
2589
* Updated easy-rsa3 bundled with the installer on Windows.
2590
2591
On Windows DCO will be used by default for client connections unless the configuration contains settings that are not DCO compatible, such as compression. DCO support on Linux requires an additional kernel module to be installed, this is available from our [OpenvpnSoftwareRepos software repositories for Linux], and is also available for OpenVPN3 Linux client.
2592
2593
| | | |
2594
|-|-|-|
2595
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta1-I001-amd64.msi.asc)|[OpenVPN-2.6_beta1-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta1-I001-amd64.msi)|
2596
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta1-I001-arm64.msi.asc)|[OpenVPN-2.6_beta1-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta1-I001-arm64.msi)|
2597
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta1-I001-x86.msi.asc)|[OpenVPN-2.6_beta1-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.6_beta1-I001-x86.msi)|
2598
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6_beta1.tar.gz.asc)|[openvpn-2.6_beta1.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6_beta1.tar.gz)|