OpenVPN 2.6.20 released

Yuriy Darnobyt <[email protected]> Wed, 22 Apr 2026 23:36:23 +0300
Newsgroups gmane.network.openvpn.devel,gmane.network.openvpn.user
Message-ID <[email protected]>
--===============7188203464439864743==
Content-Type: multipart/alternative;
	boundary="Apple-Mail=_EE4F78C7-F728-4299-9B8D-A66DADE7D525"


--Apple-Mail=_EE4F78C7-F728-4299-9B8D-A66DADE7D525
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=us-ascii

The OpenVPN community project team is proud to release OpenVPN 2.6.20. =
This is a bugfix release containing security fixes.

For details see =
[Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.20/Changes.rst)=


Security fixes:

* CVE-2026-40215: fix race condition in TLS handshake that could lead to =
leaking of
  packet data from a previous handshake under specific circumstances
* CVE-2026-35058: fix server ASSERT() on receiving a suitably malformed =
packet with
  a valid tls-crypt-v2 key
 =20
Bugfixes:

* management: stop periodic bytecount output on mgmt client =
disconnection
* FreeBSD: make DCO work on systems with no IPv4 support
* FreeBSD: fix compilation with --enable-async-push on FreeBSD 15
* Linux: make DCO work on big endian architectures (MIPS, PowerPC)
* Windows: fix deinstallation progress bar on adapter deletion.
* Linux: fix problem with DCO kernel notifications getting lost, leading
  to overcounting of number of connected clients and general confusion
  between kernel and userland regarding peer status (Github openvpn#900,
  openvpn#918, openvpn#931, openvpn#919, openvpn#945) - this is a =
backport of
  the fixes in 2.7 plus the infrastructural changes around DCO needed to =
support it.

Windows MSI changes since 2.6.19-I001:
* Built against OpenSSL 3.6.2
* Included openvpn-gui updated to 11.63.0.0
  * Translation cleanup. Remove obsolete strings related to support for =
OpenVPN < 2.0
  * Translation updates.

More details can be found in the Changes document:

<https://github.com/OpenVPN/openvpn/blob/v2.6.20/Changes.rst =
<https://github.com/OpenVPN/openvpn/blob/v2./Changes.rst>>

Source code and Windows installers can be downloaded from our download =
page:

<https://openvpn.net/community/>

Packages for Debian, Ubuntu, Fedora, RHEL, and openSUSE are available in =
the various
official Community repositories:

<https://community.openvpn.net/Pages/OpenVPN%20software%20repos>

Kind regards,
Yuriy Darnobyt=

--Apple-Mail=_EE4F78C7-F728-4299-9B8D-A66DADE7D525
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=us-ascii

<html aria-label=3D"message body"><head><meta http-equiv=3D"content-type" =
content=3D"text/html; charset=3Dus-ascii"></head><body =
style=3D"overflow-wrap: break-word; -webkit-nbsp-mode: space; =
line-break: after-white-space;"><div><div>The OpenVPN community project =
team is proud to release OpenVPN 2.6.20. This is a bugfix release =
containing security fixes.</div><div><br></div><div>For details see =
[Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.20/Changes.rst)=
</div><div><br></div><div>Security fixes:</div><div><br></div><div>* =
CVE-2026-40215: fix race condition in TLS handshake that could lead to =
leaking of</div><div>&nbsp; packet data from a previous handshake under =
specific circumstances</div><div>* CVE-2026-35058: fix server ASSERT() =
on receiving a suitably malformed packet with</div><div>&nbsp; a valid =
tls-crypt-v2 =
key</div><div>&nbsp;&nbsp;</div><div>Bugfixes:</div><div><br></div><div>* =
management: stop periodic bytecount output on mgmt client =
disconnection</div><div>* FreeBSD: make DCO work on systems with no IPv4 =
support</div><div>* FreeBSD: fix compilation with --enable-async-push on =
FreeBSD 15</div><div>* Linux: make DCO work on big endian architectures =
(MIPS, PowerPC)</div><div>* Windows: fix deinstallation progress bar on =
adapter deletion.</div><div>* Linux: fix problem with DCO kernel =
notifications getting lost, leading</div><div>&nbsp; to overcounting of =
number of connected clients and general confusion</div><div>&nbsp; =
between kernel and userland regarding peer status (Github =
openvpn#900,</div><div>&nbsp; openvpn#918, openvpn#931, openvpn#919, =
openvpn#945) - this is a backport of</div><div>&nbsp; the fixes in 2.7 =
plus the infrastructural changes around DCO needed to support =
it.</div><div><br></div><div>Windows MSI changes since =
2.6.19-I001:</div><div>* Built against OpenSSL 3.6.2</div><div>* =
Included openvpn-gui updated to 11.63.0.0</div><div>&nbsp; * Translation =
cleanup. Remove obsolete strings related to support for OpenVPN &lt; =
2.0</div><div>&nbsp; * Translation updates.</div></div><br>More details =
can be found in the Changes document:<br><br>&lt;<a =
href=3D"https://github.com/OpenVPN/openvpn/blob/v2./Changes.rst">https://g=
ithub.com/OpenVPN/openvpn/blob/v2.6.20/Changes.rst</a>&gt;<br><br>Source =
code and Windows installers can be downloaded from our download =
page:<br><br>&lt;<a =
href=3D"https://openvpn.net/community/">https://openvpn.net/community/</a>=
&gt;<br><br>Packages for Debian, Ubuntu, Fedora, RHEL, and openSUSE are =
available in the various<br>official Community =
repositories:<br><br>&lt;<a =
href=3D"https://community.openvpn.net/Pages/OpenVPN%20software%20repos">ht=
tps://community.openvpn.net/Pages/OpenVPN%20software%20repos</a>&gt;<div><=
br></div><div><p style=3D"margin: 0px; font-style: normal; =
font-variant-caps: normal; font-width: normal; line-height: normal; =
font-size-adjust: none; font-kerning: auto; font-variant-alternates: =
normal; font-variant-ligatures: normal; font-variant-numeric: normal; =
font-variant-east-asian: normal; font-variant-position: normal; =
font-variant-emoji: normal; font-feature-settings: normal; =
font-optical-sizing: auto; font-variation-settings: normal; color: =
rgb(0, 0, 0); -webkit-text-stroke-width: 0px; -webkit-text-stroke-color: =
rgb(0, 0, 0);"><span style=3D"font-kerning: none">Kind =
regards,</span></p>
<p style=3D"margin: 0px; font-style: normal; font-variant-caps: normal; =
font-width: normal; line-height: normal; font-size-adjust: none; =
font-kerning: auto; font-variant-alternates: normal; =
font-variant-ligatures: normal; font-variant-numeric: normal; =
font-variant-east-asian: normal; font-variant-position: normal; =
font-variant-emoji: normal; font-feature-settings: normal; =
font-optical-sizing: auto; font-variation-settings: normal; color: =
rgb(0, 0, 0); -webkit-text-stroke-width: 0px; -webkit-text-stroke-color: =
rgb(0, 0, 0);"><span style=3D"font-kerning: none">Yuriy =
Darnobyt</span></p></div></body></html>=

--Apple-Mail=_EE4F78C7-F728-4299-9B8D-A66DADE7D525--


--===============7188203464439864743==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============7188203464439864743==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Openvpn-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-devel

--===============7188203464439864743==--