The OpenVPN community project team is proud to release OpenVPN 2.7.8.
This is a bugfix release fixing several security issues.
Security fixes:
* Check for NULL-Bytes in certificate subjects - refuse all such certificates
now as
"invalid" (CVE-2026-84790).
(Bug reported by Vivek Parikh)
* TLS handshake with tls-crypt-v2: do not try to add a wrapped client key if no
key
material is available (client bug in response to an ill-behaving server).
(No CVE assigned as "a malicious server can stop the client from working
properly"
is not considered a CVE-worthy security issue according to the CRA guidelines)
* options: fix unsigned underflow when clearing domain_search_list
(CVE-2026-88964)
(Bug reported and fix contributed by Cole Munz)
* win32: stop cmd.exe from expanding variables in quoted arguments
(CVE-2026-84256)
(Bug reported by Darren Carreras)
User-visible Changes:
* Certificate validation is now stricter regarding NULL bytes in strings (see
above). This might break existing installations if such certificates exist
and
OpenSSL builds are used. mbedTLS builds always rejected this.
* On a certificate with duplicate fields (multiple CN, for example) OpenSSL
builds
would use the last one, mbedTLS builds use the first one - changed in the
mbedTLS
build so behaviour is identical.
Bugfixes:
* DCO: remove installed iroutes at client exit time, not at delayed multi
instance
cleanup time - otherwise there is a race with reconnecting clients, possibly
ending
up having "no iroutes installed in the system at all". Bug reported by
OpenVPN Inc
Access Server team.
* DCO Linux: fix remaining races between synchronous netlink operations and
incoming
asynchronous notifications, by adding a second netlink socket and strictly
separating sync/async operations.
* Client: refuse incoming pushed option combination of epoch data format with
non-AEAD ciphers
(restart session instead of aborting with a fatal error).
* DCO (Linux and Windows): on failures to set up a new peer or install key
materials for a
peer, do not exit OpenVPN with a fatal error. Instead, signal the error up
the call-chain and
restart the (multi) instance.
* The handshake is inherently racy when a peer is removed kernel-side due to
transport errors
or timeouts, and userland does not yet know this and wants to, for example,
install new keys.
This is fatal for the particular client instance, but must not end the whole
server process.
* DCO: stop fetching peer stats during client disconnect The intention of the
original code
was to ensure reported counters are always correct, but it did not work
(because at query
time, the peer in kernel is already gone, so we only got an error message) -
and very
inefficiently so (because we queried all the peers all the time).
End-of-session final counter
values will be implemented properly by a followup patch leveraging counters
piggybacked on the
kernel's "DEL_PEER" notification message.
* p2mp server: improve handling of mbuf lists in the face of broadcast or
multicast traffic,
and fix a bug on client exit that could lead to a server queue deadlock in
very particular
scenarios.
Windows MSI changes since 2.7.7-I001:
* Update included dco-win driver to v2.8.13
* CVE-2026-105390 - a locking flaw allowed a local user with access to the
driver's device
to cause a system deadlock and denial of service, hanging the host until it
was
power-cycled.
* Performance improvements by moving to multi-core data processing.
* See <https://github.com/OpenVPN/ovpn-dco-win/releases/tag/2.8.13> for
details.
* Update included OpenSSL to 3.6.5
* Update included Easy-RSA to 3.2.7
More details can be found in the Changes document:
<https://github.com/OpenVPN/openvpn/blob/v2.7.8/Changes.rst>
Source code and Windows installers can be downloaded from our download page:
<https://openvpn.net/community/>
Packages for Debian, Ubuntu, Fedora, RHEL, and openSUSE are available in the
various
official Community repositories:
<https://community.openvpn.net/Pages/OpenVPN%20software%20repos>
Kind regards,
--
Frank Lichtenheld
_______________________________________________
Openvpn-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-users