OpenVPN 2.7.2 released

Yuriy Darnobyt <[email protected]>
Newsgroups gmane.network.openvpn.devel,gmane.network.openvpn.user
Message-ID <[email protected]>
The OpenVPN community project team is proud to release OpenVPN 2.7.2.
This is a bugfix release containing security fixes.


Security fixes:

* CVE-2026-40215: fix race condition in TLS handshake that could lead to leaking of
  packet data from a previous handshake under specific circumstances
* CVE-2026-35058: fix server ASSERT() on receiving a suitably malformed packet with
  a valid tls-crypt-v2 key

New features:

* management interface: permit input of very long passwords in
  base64-encoded multiline format.  Signal support to management
  clients via "management version 6".

User-visible Changes:

* improve error messages on ``--verify-x509-name`` failures
* improve error logging when overlong username or passwords can not
  be written to TLS buffer

Bugfixes:

* when using a config file with inlined username and no password,
  fix prompting for the password from management interface.
* Windows: fix DNSSEC flag handling - this got never applied due to
  a bad comparison being always false.
* Windows: fix deinstallation progress bar on adapter deletion.

Windows MSI changes since 2.7.1:
* Built against OpenSSL 3.6.2
* Included openvpn-gui updated to 11.63.0.0
  * Translation cleanup. Remove obsolete strings related to support for OpenVPN < 2.0
  * Translation updates.

More details can be found in the Changes document:

<https://github.com/OpenVPN/openvpn/blob/v2.7.2/Changes.rst <https://github.com/OpenVPN/openvpn/blob/v2.7./Changes.rst>>

Source code and Windows installers can be downloaded from our download page:

<https://openvpn.net/community/>

Packages for Debian, Ubuntu, Fedora, RHEL, and openSUSE are available in the various
official Community repositories:

<https://community.openvpn.net/Pages/OpenVPN%20software%20repos>

_______________________________________________
Openvpn-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.