The OpenVPN community project team is proud to release OpenVPN 2.7.2.
This is a bugfix release containing security fixes.


Security fixes:

* CVE-2026-40215: fix race condition in TLS handshake that could lead to 
leaking of
  packet data from a previous handshake under specific circumstances
* CVE-2026-35058: fix server ASSERT() on receiving a suitably malformed packet 
with
  a valid tls-crypt-v2 key

New features:

* management interface: permit input of very long passwords in
  base64-encoded multiline format.  Signal support to management
  clients via "management version 6".

User-visible Changes:

* improve error messages on ``--verify-x509-name`` failures
* improve error logging when overlong username or passwords can not
  be written to TLS buffer

Bugfixes:

* when using a config file with inlined username and no password,
  fix prompting for the password from management interface.
* Windows: fix DNSSEC flag handling - this got never applied due to
  a bad comparison being always false.
* Windows: fix deinstallation progress bar on adapter deletion.

Windows MSI changes since 2.7.1:
* Built against OpenSSL 3.6.2
* Included openvpn-gui updated to 11.63.0.0
  * Translation cleanup. Remove obsolete strings related to support for OpenVPN 
< 2.0
  * Translation updates.

More details can be found in the Changes document:

<https://github.com/OpenVPN/openvpn/blob/v2.7.2/Changes.rst 
<https://github.com/OpenVPN/openvpn/blob/v2.7./Changes.rst>>

Source code and Windows installers can be downloaded from our download page:

<https://openvpn.net/community/>

Packages for Debian, Ubuntu, Fedora, RHEL, and openSUSE are available in the 
various
official Community repositories:

<https://community.openvpn.net/Pages/OpenVPN%20software%20repos>
_______________________________________________
Openvpn-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-users

Reply via email to