OpenVPN 2.6.7 released
Yuriy Darnobyt <[email protected]> Thu, 9 Nov 2023 22:56:10 +0200
| Newsgroups | gmane.network.openvpn.announce |
|---|---|
| Message-ID | <13E5C41C-8358-4252-A751-8FDA9EE95B7D__35976.552024816$1699563531$gmane$org@openvpn.com> |
--===============0299969956968896846== Content-Type: multipart/alternative; boundary="Apple-Mail=_09E118A3-BFB6-412F-8585-F7992CCA2377" --Apple-Mail=_09E118A3-BFB6-412F-8585-F7992CCA2377 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=us-ascii The OpenVPN community project team is proud to release OpenVPN 2.6.7. This is a bugfix release containing security fixes. Security Fixes: * CVE-2023-46850 OpenVPN versions between 2.6.0 and 2.6.6 incorrectly = use a send buffer after it has been free()d in some circumstances, causing some free()d memory = to be sent to the peer. All configurations using TLS (e.g. not using --secret) are affected by = this issue. (found while tracking down CVE-2023-46849 / Github #400, #417) * CVE-2023-46849 OpenVPN versions between 2.6.0 and 2.6.6 incorrectly = restore --fragment configuration in some circumstances, leading to a division by zero when --fragment is = used. On platforms where division by zero is fatal, this will cause an OpenVPN crash.(Github = #400, #417). User visible changes: * DCO: warn if DATA_V1 packets are sent by the other side - this a hard = incompatibility between a 2.6.x client connecting to a 2.4.0-2.4.4 server, and the only fix is = to use --disable-dco. * Remove OpenSSL Engine method for loading a key. This had to be removed = because the original author did not agree to relicensing the code with the new linking exception = added. This was a somewhat obsolete feature anyway as it only worked with OpenSSL 1.x, which is = end-of-support. * add warning if p2p NCP client connects to a p2mp server - this is a = combination that used to work without cipher negotiation (pre 2.6 on both ends), but would fail in = non-obvious ways with 2.6 to 2.6. * add warning to --show-groups that not all supported groups are listed = (this is due the internal enumeration in OpenSSL being a bit weird, omitting = X448 and X25519 curves). * --dns: remove support for exclude-domains argument (this was a new 2.6 = option, with no backend support implemented yet on any platform, and it turns = out that=20 no platform supported it at all - so remove option again) * warn user if INFO control message too long, do not forward to = management client (safeguard against protocol-violating server implementations) New features: * DCO-WIN: get and log driver version (for easier debugging). * print "peer temporary key details" in TLS handshake * log OpenSSL errors on failure to set certificate, for example if the = algorithms used=20 are in acceptable to OpenSSL (misleading message would be printed in = cryptoapi / pkcs11 scenarios) * add CMake build system for MinGW and MSVC builds * remove old MSVC build system * improve cmocka unit test building for Windows Windows MSI changes since 2.6.6: * Included openvpn-gui updated to 11.45.0.0 * Add clarity for error on missing management parameter. See GH #657 * Improve "OpenVPN GUI" tooltip handling See GH #649 * MSIs now use OpenSSL 3.1.4 More details can be found in the Changes document: <https://github.com/OpenVPN/openvpn/blob/release/2.6/Changes.rst> (The Changes document also contains a section with work-arounds for common problems encountered when using OpenVPN with OpenSSL 3) Source code and Windows installers can be downloaded from our download = page: <https://openvpn.net/community-downloads/> Debian and Ubuntu packages are available in the official apt = repositories: = <https://community.openvpn.net/openvpn/wiki/OpenvpnSoftwareRepos#DebianUbu= ntu:UsingOpenVPNaptrepositories> On Red Hat derivatives we recommend using the Fedora Copr repository. <https://copr.fedorainfracloud.org/coprs/dsommers/openvpn-release-2.6/> Kind regards, Yuriy Darnobyt= --Apple-Mail=_09E118A3-BFB6-412F-8585-F7992CCA2377 Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=us-ascii <html><head><meta http-equiv=3D"content-type" content=3D"text/html; = charset=3Dus-ascii"></head><body style=3D"overflow-wrap: break-word; = -webkit-nbsp-mode: space; line-break: after-white-space;"><span = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">The OpenVPN = community project team is proud to release OpenVPN 2.6.7.</span><br = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><br = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><span = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">This is a = bugfix release containing security fixes.</span><br style=3D"caret-color: = rgb(0, 0, 0); color: rgb(0, 0, 0);"><br style=3D"caret-color: rgb(0, 0, = 0); color: rgb(0, 0, 0);"><span style=3D"caret-color: rgb(0, 0, 0); = color: rgb(0, 0, 0);">Security Fixes:</span><br style=3D"caret-color: = rgb(0, 0, 0); color: rgb(0, 0, 0);"><br style=3D"caret-color: rgb(0, 0, = 0); color: rgb(0, 0, 0);"><span style=3D"caret-color: rgb(0, 0, 0); = color: rgb(0, 0, 0);">* CVE-2023-46850 OpenVPN versions between 2.6.0 = and 2.6.6 incorrectly use a send buffer after</span><br = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><span = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"> it has = been free()d in some circumstances, causing some free()d memory to be = sent to the peer.</span><br style=3D"caret-color: rgb(0, 0, 0); color: = rgb(0, 0, 0);"><span style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, = 0, 0);"> All configurations using TLS (e.g. not using --secret) are = affected by this issue.</span><br style=3D"caret-color: rgb(0, 0, 0); = color: rgb(0, 0, 0);"><span style=3D"caret-color: rgb(0, 0, 0); color: = rgb(0, 0, 0);"> (found while tracking down CVE-2023-46849 / Github = #400, #417)</span><br style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, = 0, 0);"><span style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, = 0);">* CVE-2023-46849 OpenVPN versions between 2.6.0 and 2.6.6 = incorrectly restore --fragment configuration</span><br = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><span = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"> in some = circumstances, leading to a division by zero when --fragment is used. On = platforms where</span><br style=3D"caret-color: rgb(0, 0, 0); color: = rgb(0, 0, 0);"><span style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, = 0, 0);"> division by zero is fatal, this will cause an OpenVPN = crash.(Github #400, #417).</span><br style=3D"caret-color: rgb(0, 0, 0); = color: rgb(0, 0, 0);"><br style=3D"caret-color: rgb(0, 0, 0); color: = rgb(0, 0, 0);"><span style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, = 0, 0);">User visible changes:</span><br style=3D"caret-color: rgb(0, 0, = 0); color: rgb(0, 0, 0);"><br style=3D"caret-color: rgb(0, 0, 0); color: = rgb(0, 0, 0);"><span style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, = 0, 0);">* DCO: warn if DATA_V1 packets are sent by the other side - this = a hard incompatibility between</span><br style=3D"caret-color: rgb(0, 0, = 0); color: rgb(0, 0, 0);"><span style=3D"caret-color: rgb(0, 0, 0); = color: rgb(0, 0, 0);"> a 2.6.x client connecting to a 2.4.0-2.4.4 = server, and the only fix is to use --disable-dco.</span><br = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><span = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">* Remove = OpenSSL Engine method for loading a key. This had to be removed because = the original author</span><br style=3D"caret-color: rgb(0, 0, 0); color: = rgb(0, 0, 0);"><span style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, = 0, 0);"> did not agree to relicensing the code with the new linking = exception added. This was a somewhat</span><br style=3D"caret-color: = rgb(0, 0, 0); color: rgb(0, 0, 0);"><span style=3D"caret-color: rgb(0, = 0, 0); color: rgb(0, 0, 0);"> obsolete feature anyway as it only = worked with OpenSSL 1.x, which is end-of-support.</span><br = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><span = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">* add warning = if p2p NCP client connects to a p2mp server - this is a combination that = used to work</span><br style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, = 0, 0);"><span style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, = 0);"> without cipher negotiation (pre 2.6 on both ends), but would = fail in non-obvious ways with 2.6 to 2.6.</span><br style=3D"caret-color: = rgb(0, 0, 0); color: rgb(0, 0, 0);"><span style=3D"caret-color: rgb(0, = 0, 0); color: rgb(0, 0, 0);">* add warning to --show-groups that not all = supported groups are listed (this is</span><br style=3D"caret-color: = rgb(0, 0, 0); color: rgb(0, 0, 0);"><span style=3D"caret-color: rgb(0, = 0, 0); color: rgb(0, 0, 0);"> due the internal enumeration in = OpenSSL being a bit weird, omitting X448 and X25519 curves).</span><br = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><span = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">* --dns: = remove support for exclude-domains argument (this was a new 2.6 = option,</span><br style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, = 0);"><span style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, = 0);"> with no backend support implemented yet on any platform, and = it turns out that </span><br style=3D"caret-color: rgb(0, 0, 0); = color: rgb(0, 0, 0);"><span style=3D"caret-color: rgb(0, 0, 0); color: = rgb(0, 0, 0);"> no platform supported it at all - so remove option = again)</span><br style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, = 0);"><span style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">* = warn user if INFO control message too long, do not forward to management = client</span><br style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, = 0);"><span style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, = 0);"> (safeguard against protocol-violating server = implementations)</span><br style=3D"caret-color: rgb(0, 0, 0); color: = rgb(0, 0, 0);"><br style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, = 0);"><span style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">New = features:</span><br style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, = 0);"><br style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><span = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">* DCO-WIN: get = and log driver version (for easier debugging).</span><br = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><span = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">* print "peer = temporary key details" in TLS handshake</span><br style=3D"caret-color: = rgb(0, 0, 0); color: rgb(0, 0, 0);"><span style=3D"caret-color: rgb(0, = 0, 0); color: rgb(0, 0, 0);">* log OpenSSL errors on failure to set = certificate, for example if the algorithms used </span><br = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><span = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"> are in = acceptable to OpenSSL (misleading message would be printed in cryptoapi = / pkcs11 scenarios)</span><br style=3D"caret-color: rgb(0, 0, 0); color: = rgb(0, 0, 0);"><span style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, = 0, 0);">* add CMake build system for MinGW and MSVC builds</span><br = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><span = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">* remove old = MSVC build system</span><br style=3D"caret-color: rgb(0, 0, 0); color: = rgb(0, 0, 0);"><span style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, = 0, 0);">* improve cmocka unit test building for Windows</span><br = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><br = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><span = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">Windows MSI = changes since 2.6.6:</span><br style=3D"caret-color: rgb(0, 0, 0); = color: rgb(0, 0, 0);"><br style=3D"caret-color: rgb(0, 0, 0); color: = rgb(0, 0, 0);"><span style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, = 0, 0);">* Included openvpn-gui updated to 11.45.0.0</span><br = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><span = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, = 0);"> * Add clarity for error on missing management = parameter. See GH #657</span><br style=3D"caret-color: rgb(0, 0, 0); = color: rgb(0, 0, 0);"><span style=3D"caret-color: rgb(0, 0, 0); color: = rgb(0, 0, 0);"> * Improve "OpenVPN GUI" tooltip = handling See GH #649</span><br style=3D"caret-color: rgb(0, 0, 0); = color: rgb(0, 0, 0);"><span style=3D"caret-color: rgb(0, 0, 0); color: = rgb(0, 0, 0);">* MSIs now use OpenSSL 3.1.4</span><br = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><br = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><span = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">More details = can be found in the Changes document:</span><br style=3D"caret-color: = rgb(0, 0, 0); color: rgb(0, 0, 0);"><br style=3D"caret-color: rgb(0, 0, = 0); color: rgb(0, 0, 0);"><span style=3D"caret-color: rgb(0, 0, 0); = color: rgb(0, 0, 0);"><</span><a = href=3D"https://github.com/OpenVPN/openvpn/blob/release/2.6/Changes.rst">h= ttps://github.com/OpenVPN/openvpn/blob/release/2.6/Changes.rst</a><span = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">></span><br = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><br = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><span = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">(The Changes = document also contains a section with work-arounds for</span><br = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><span = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">common = problems encountered when using OpenVPN with OpenSSL 3)</span><br = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><br = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><span = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">Source code = and Windows installers can be downloaded from our download = page:</span><br style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, = 0);"><br style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><span = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><</span><a = href=3D"https://openvpn.net/community-downloads/">https://openvpn.net/comm= unity-downloads/</a><span style=3D"caret-color: rgb(0, 0, 0); color: = rgb(0, 0, 0);">></span><br style=3D"caret-color: rgb(0, 0, 0); color: = rgb(0, 0, 0);"><br style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, = 0);"><span style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, = 0);">Debian and Ubuntu packages are available in the official apt = repositories:</span><br style=3D"caret-color: rgb(0, 0, 0); color: = rgb(0, 0, 0);"><br style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, = 0);"><span style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, = 0);"><</span><a = href=3D"https://community.openvpn.net/openvpn/wiki/OpenvpnSoftwareRepos#De= bianUbuntu:UsingOpenVPNaptrepositories">https://community.openvpn.net/open= vpn/wiki/OpenvpnSoftwareRepos#DebianUbuntu:UsingOpenVPNaptrepositories</a>= <span style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, = 0);">></span><br style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, = 0);"><br style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><span = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">On Red Hat = derivatives we recommend using the Fedora Copr repository.</span><br = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><br = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><span = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><</span><a = href=3D"https://copr.fedorainfracloud.org/coprs/dsommers/openvpn-release-2= .6/">https://copr.fedorainfracloud.org/coprs/dsommers/openvpn-release-2.6/= </a><span style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, = 0);">></span><br style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, = 0);"><br style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><span = style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">Kind = regards,</span><br style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, = 0);"><span style=3D"caret-color: rgb(0, 0, 0); color: rgb(0, 0, = 0);">Yuriy Darnobyt</span></body></html>= --Apple-Mail=_09E118A3-BFB6-412F-8585-F7992CCA2377-- --===============0299969956968896846== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============0299969956968896846== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Openvpn-announce mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/openvpn-announce --===============0299969956968896846==--