Hi,

Does anybody know why the EPEL openvpn RPMs are not updated anymore? They are 
still at version 2.7.6.

Thanks,
Simon


Am 7. Oktober 2026 um 18:39 schrieb "Frank Lichtenheld" <[email protected] 
mailto:[email protected]?to=%22Frank%20Lichtenheld%22%20%3Cfrank%40lichtenheld.com%3E
 >:


> 
> The OpenVPN community project team is proud to release OpenVPN 2.7.8.
> This is a bugfix release fixing several security issues.
> 
> Security fixes:
> 
> * Check for NULL-Bytes in certificate subjects - refuse all such certificates 
> now as 
>  "invalid" (CVE-2026-84790).
>  (Bug reported by Vivek Parikh)
> * TLS handshake with tls-crypt-v2: do not try to add a wrapped client key if 
> no key 
>  material is available (client bug in response to an ill-behaving server).
>  (No CVE assigned as "a malicious server can stop the client from working 
> properly" 
>  is not considered a CVE-worthy security issue according to the CRA 
> guidelines)
> * options: fix unsigned underflow when clearing domain_search_list 
> (CVE-2026-88964)
>  (Bug reported and fix contributed by Cole Munz)
> * win32: stop cmd.exe from expanding variables in quoted arguments 
> (CVE-2026-84256)
>  (Bug reported by Darren Carreras)
> 
> User-visible Changes:
> 
> * Certificate validation is now stricter regarding NULL bytes in strings (see 
>  above). This might break existing installations if such certificates exist 
> and 
>  OpenSSL builds are used. mbedTLS builds always rejected this.
> * On a certificate with duplicate fields (multiple CN, for example) OpenSSL 
> builds 
>  would use the last one, mbedTLS builds use the first one - changed in the 
> mbedTLS 
>  build so behaviour is identical.
> 
> Bugfixes:
> 
> * DCO: remove installed iroutes at client exit time, not at delayed multi 
> instance 
>  cleanup time - otherwise there is a race with reconnecting clients, possibly 
> ending 
>  up having "no iroutes installed in the system at all". Bug reported by 
> OpenVPN Inc 
>  Access Server team.
> * DCO Linux: fix remaining races between synchronous netlink operations and 
> incoming 
>  asynchronous notifications, by adding a second netlink socket and strictly
>  separating sync/async operations.
> * Client: refuse incoming pushed option combination of epoch data format with 
> non-AEAD ciphers 
>  (restart session instead of aborting with a fatal error).
> * DCO (Linux and Windows): on failures to set up a new peer or install key 
> materials for a 
>  peer, do not exit OpenVPN with a fatal error. Instead, signal the error up 
> the call-chain and 
>  restart the (multi) instance.
> * The handshake is inherently racy when a peer is removed kernel-side due to 
> transport errors 
>  or timeouts, and userland does not yet know this and wants to, for example, 
> install new keys. 
>  This is fatal for the particular client instance, but must not end the whole 
> server process.
> * DCO: stop fetching peer stats during client disconnect The intention of the 
> original code 
>  was to ensure reported counters are always correct, but it did not work 
> (because at query 
>  time, the peer in kernel is already gone, so we only got an error message) - 
> and very 
>  inefficiently so (because we queried all the peers all the time). 
> End-of-session final counter 
>  values will be implemented properly by a followup patch leveraging counters 
> piggybacked on the 
>  kernel's "DEL_PEER" notification message.
> * p2mp server: improve handling of mbuf lists in the face of broadcast or 
> multicast traffic, 
>  and fix a bug on client exit that could lead to a server queue deadlock in 
> very particular 
>  scenarios.
> 
> Windows MSI changes since 2.7.7-I001:
> 
> * Update included dco-win driver to v2.8.13
>  * CVE-2026-105390 - a locking flaw allowed a local user with access to the 
> driver's device 
>  to cause a system deadlock and denial of service, hanging the host until it 
> was 
>  power-cycled.
>  * Performance improvements by moving to multi-core data processing.
>  * See <https://github.com/OpenVPN/ovpn-dco-win/releases/tag/2.8.13> 
> https://github.com/OpenVPN/ovpn-dco-win/releases/tag/2.8.13%3E  for details.
> * Update included OpenSSL to 3.6.5
> * Update included Easy-RSA to 3.2.7
> 
> More details can be found in the Changes document:
> 
> <https://github.com/OpenVPN/openvpn/blob/v2.7.8/Changes.rst> 
> https://github.com/OpenVPN/openvpn/blob/v2.7.8/Changes.rst%3E 
> 
> Source code and Windows installers can be downloaded from our download page:
> 
> <https://openvpn.net/community/> https://openvpn.net/community/%3E 
> 
> Packages for Debian, Ubuntu, Fedora, RHEL, and openSUSE are available in the 
> various
> official Community repositories:
> 
> <https://community.openvpn.net/Pages/OpenVPN%20software%20repos> 
> https://community.openvpn.net/Pages/OpenVPN%20software%20repos%3E 
> 
> Kind regards,
> -- 
>  Frank Lichtenheld
> 
> _______________________________________________
> Openvpn-users mailing list
> [email protected] 
> mailto:[email protected] 
> https://lists.sourceforge.net/lists/listinfo/openvpn-users
> 

-- 
Simon Matter Tel: +41 61 311 40 70
Glasiweg 8b
CH-6242 Wauwil
_______________________________________________
Openvpn-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-users

Reply via email to