The OpenVPN community project team is proud to release OpenVPN 2.7.2.
This is a bugfix release containing security fixes.
Security fixes:
* CVE-2026-40215: fix race condition in TLS handshake that could lead to
leaking of
packet data from a previous handshake under specific circumstances
* CVE-2026-35058: fix server ASSERT() on receiving a suitably malformed packet
with
a valid tls-crypt-v2 key
New features:
* management interface: permit input of very long passwords in
base64-encoded multiline format. Signal support to management
clients via "management version 6".
User-visible Changes:
* improve error messages on ``--verify-x509-name`` failures
* improve error logging when overlong username or passwords can not
be written to TLS buffer
Bugfixes:
* when using a config file with inlined username and no password,
fix prompting for the password from management interface.
* Windows: fix DNSSEC flag handling - this got never applied due to
a bad comparison being always false.
* Windows: fix deinstallation progress bar on adapter deletion.
Windows MSI changes since 2.7.1:
* Built against OpenSSL 3.6.2
* Included openvpn-gui updated to 11.63.0.0
* Translation cleanup. Remove obsolete strings related to support for OpenVPN
< 2.0
* Translation updates.
More details can be found in the Changes document:
<https://github.com/OpenVPN/openvpn/blob/v2.7.2/Changes.rst
<https://github.com/OpenVPN/openvpn/blob/v2.7./Changes.rst>>
Source code and Windows installers can be downloaded from our download page:
<https://openvpn.net/community/>
Packages for Debian, Ubuntu, Fedora, RHEL, and openSUSE are available in the
various
official Community repositories:
<https://community.openvpn.net/Pages/OpenVPN%20software%20repos>
_______________________________________________
Openvpn-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-users