The OpenVPN community project team is proud to release OpenVPN 2.7.8.
This is a bugfix release fixing several security issues.

Security fixes:

* Check for NULL-Bytes in certificate subjects - refuse all such certificates 
now as 
  "invalid" (CVE-2026-84790).
  (Bug reported by Vivek Parikh)
* TLS handshake with tls-crypt-v2: do not try to add a wrapped client key if no 
key 
  material is available (client bug in response to an ill-behaving server).
  (No CVE assigned as "a malicious server can stop the client from working 
properly" 
  is not considered a CVE-worthy security issue according to the CRA guidelines)
* options: fix unsigned underflow when clearing domain_search_list 
(CVE-2026-88964)
  (Bug reported and fix contributed by Cole Munz)
* win32: stop cmd.exe from expanding variables in quoted arguments 
(CVE-2026-84256)
  (Bug reported by Darren Carreras)

User-visible Changes:

* Certificate validation is now stricter regarding NULL bytes in strings (see 
  above). This might break existing installations if such certificates exist 
and 
  OpenSSL builds are used. mbedTLS builds always rejected this.
* On a certificate with duplicate fields (multiple CN, for example) OpenSSL 
builds 
  would use the last one, mbedTLS builds use the first one - changed in the 
mbedTLS 
  build so behaviour is identical.

Bugfixes:

* DCO: remove installed iroutes at client exit time, not at delayed multi 
instance 
  cleanup time - otherwise there is a race with reconnecting clients, possibly 
ending 
  up having "no iroutes installed in the system at all". Bug reported by 
OpenVPN Inc 
  Access Server team.
* DCO Linux: fix remaining races between synchronous netlink operations and 
incoming 
  asynchronous notifications, by adding a second netlink socket and strictly
  separating sync/async operations.
* Client: refuse incoming pushed option combination of epoch data format with 
non-AEAD ciphers 
  (restart session instead of aborting with a fatal error).
* DCO (Linux and Windows): on failures to set up a new peer or install key 
materials for a 
  peer, do not exit OpenVPN with a fatal error. Instead, signal the error up 
the call-chain and 
  restart the (multi) instance.
* The handshake is inherently racy when a peer is removed kernel-side due to 
transport errors 
  or timeouts, and userland does not yet know this and wants to, for example, 
install new keys. 
  This is fatal for the particular client instance, but must not end the whole 
server process.
* DCO: stop fetching peer stats during client disconnect The intention of the 
original code 
  was to ensure reported counters are always correct, but it did not work 
(because at query 
  time, the peer in kernel is already gone, so we only got an error message) - 
and very 
  inefficiently so (because we queried all the peers all the time). 
End-of-session final counter 
  values will be implemented properly by a followup patch leveraging counters 
piggybacked on the 
  kernel's "DEL_PEER" notification message.
* p2mp server: improve handling of mbuf lists in the face of broadcast or 
multicast traffic, 
  and fix a bug on client exit that could lead to a server queue deadlock in 
very particular 
  scenarios.

Windows MSI changes since 2.7.7-I001:

* Update included dco-win driver to v2.8.13
  * CVE-2026-105390 - a locking flaw allowed a local user with access to the 
driver's device 
    to cause a system deadlock and denial of service, hanging the host until it 
was 
    power-cycled.
  * Performance improvements by moving to multi-core data processing.
  * See <https://github.com/OpenVPN/ovpn-dco-win/releases/tag/2.8.13> for 
details.
* Update included OpenSSL to 3.6.5
* Update included Easy-RSA to 3.2.7

More details can be found in the Changes document:

<https://github.com/OpenVPN/openvpn/blob/v2.7.8/Changes.rst>

Source code and Windows installers can be downloaded from our download page:

<https://openvpn.net/community/>

Packages for Debian, Ubuntu, Fedora, RHEL, and openSUSE are available in the 
various
official Community repositories:

<https://community.openvpn.net/Pages/OpenVPN%20software%20repos>

Kind regards,
-- 
  Frank Lichtenheld


_______________________________________________
Openvpn-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-users

Reply via email to