|
From: Frank L. <fr...@li...> - 2026-10-07 16:40:22
|
The OpenVPN community project team is proud to release OpenVPN 2.7.8.
This is a bugfix release fixing several security issues.
Security fixes:
* Check for NULL-Bytes in certificate subjects - refuse all such certificates now as
"invalid" (CVE-2026-84790).
(Bug reported by Vivek Parikh)
* TLS handshake with tls-crypt-v2: do not try to add a wrapped client key if no key
material is available (client bug in response to an ill-behaving server).
(No CVE assigned as "a malicious server can stop the client from working properly"
is not considered a CVE-worthy security issue according to the CRA guidelines)
* options: fix unsigned underflow when clearing domain_search_list (CVE-2026-88964)
(Bug reported and fix contributed by Cole Munz)
* win32: stop cmd.exe from expanding variables in quoted arguments (CVE-2026-84256)
(Bug reported by Darren Carreras)
User-visible Changes:
* Certificate validation is now stricter regarding NULL bytes in strings (see
above). This might break existing installations if such certificates exist and
OpenSSL builds are used. mbedTLS builds always rejected this.
* On a certificate with duplicate fields (multiple CN, for example) OpenSSL builds
would use the last one, mbedTLS builds use the first one - changed in the mbedTLS
build so behaviour is identical.
Bugfixes:
* DCO: remove installed iroutes at client exit time, not at delayed multi instance
cleanup time - otherwise there is a race with reconnecting clients, possibly ending
up having "no iroutes installed in the system at all". Bug reported by OpenVPN Inc
Access Server team.
* DCO Linux: fix remaining races between synchronous netlink operations and incoming
asynchronous notifications, by adding a second netlink socket and strictly
separating sync/async operations.
* Client: refuse incoming pushed option combination of epoch data format with non-AEAD ciphers
(restart session instead of aborting with a fatal error).
* DCO (Linux and Windows): on failures to set up a new peer or install key materials for a
peer, do not exit OpenVPN with a fatal error. Instead, signal the error up the call-chain and
restart the (multi) instance.
* The handshake is inherently racy when a peer is removed kernel-side due to transport errors
or timeouts, and userland does not yet know this and wants to, for example, install new keys.
This is fatal for the particular client instance, but must not end the whole server process.
* DCO: stop fetching peer stats during client disconnect The intention of the original code
was to ensure reported counters are always correct, but it did not work (because at query
time, the peer in kernel is already gone, so we only got an error message) - and very
inefficiently so (because we queried all the peers all the time). End-of-session final counter
values will be implemented properly by a followup patch leveraging counters piggybacked on the
kernel's "DEL_PEER" notification message.
* p2mp server: improve handling of mbuf lists in the face of broadcast or multicast traffic,
and fix a bug on client exit that could lead to a server queue deadlock in very particular
scenarios.
Windows MSI changes since 2.7.7-I001:
* Update included dco-win driver to v2.8.13
* CVE-2026-105390 - a locking flaw allowed a local user with access to the driver's device
to cause a system deadlock and denial of service, hanging the host until it was
power-cycled.
* Performance improvements by moving to multi-core data processing.
* See <https://github.com/OpenVPN/ovpn-dco-win/releases/tag/2.8.13> for details.
* Update included OpenSSL to 3.6.5
* Update included Easy-RSA to 3.2.7
More details can be found in the Changes document:
<https://github.com/OpenVPN/openvpn/blob/v2.7.8/Changes.rst>
Source code and Windows installers can be downloaded from our download page:
<https://openvpn.net/community/>
Packages for Debian, Ubuntu, Fedora, RHEL, and openSUSE are available in the various
official Community repositories:
<https://community.openvpn.net/Pages/OpenVPN%20software%20repos>
Kind regards,
--
Frank Lichtenheld
|