Hi,
Does anybody know why the EPEL openvpn RPMs are not updated anymore? They are
still at version 2.7.6.
Thanks,
Simon
Am 7. Oktober 2026 um 18:39 schrieb "Frank Lichtenheld" <[email protected]
mailto:[email protected]?to=%22Frank%20Lichtenheld%22%20%3Cfrank%40lichtenheld.com%3E
>:
>
> The OpenVPN community project team is proud to release OpenVPN 2.7.8.
> This is a bugfix release fixing several security issues.
>
> Security fixes:
>
> * Check for NULL-Bytes in certificate subjects - refuse all such certificates
> now as
> "invalid" (CVE-2026-84790).
> (Bug reported by Vivek Parikh)
> * TLS handshake with tls-crypt-v2: do not try to add a wrapped client key if
> no key
> material is available (client bug in response to an ill-behaving server).
> (No CVE assigned as "a malicious server can stop the client from working
> properly"
> is not considered a CVE-worthy security issue according to the CRA
> guidelines)
> * options: fix unsigned underflow when clearing domain_search_list
> (CVE-2026-88964)
> (Bug reported and fix contributed by Cole Munz)
> * win32: stop cmd.exe from expanding variables in quoted arguments
> (CVE-2026-84256)
> (Bug reported by Darren Carreras)
>
> User-visible Changes:
>
> * Certificate validation is now stricter regarding NULL bytes in strings (see
> above). This might break existing installations if such certificates exist
> and
> OpenSSL builds are used. mbedTLS builds always rejected this.
> * On a certificate with duplicate fields (multiple CN, for example) OpenSSL
> builds
> would use the last one, mbedTLS builds use the first one - changed in the
> mbedTLS
> build so behaviour is identical.
>
> Bugfixes:
>
> * DCO: remove installed iroutes at client exit time, not at delayed multi
> instance
> cleanup time - otherwise there is a race with reconnecting clients, possibly
> ending
> up having "no iroutes installed in the system at all". Bug reported by
> OpenVPN Inc
> Access Server team.
> * DCO Linux: fix remaining races between synchronous netlink operations and
> incoming
> asynchronous notifications, by adding a second netlink socket and strictly
> separating sync/async operations.
> * Client: refuse incoming pushed option combination of epoch data format with
> non-AEAD ciphers
> (restart session instead of aborting with a fatal error).
> * DCO (Linux and Windows): on failures to set up a new peer or install key
> materials for a
> peer, do not exit OpenVPN with a fatal error. Instead, signal the error up
> the call-chain and
> restart the (multi) instance.
> * The handshake is inherently racy when a peer is removed kernel-side due to
> transport errors
> or timeouts, and userland does not yet know this and wants to, for example,
> install new keys.
> This is fatal for the particular client instance, but must not end the whole
> server process.
> * DCO: stop fetching peer stats during client disconnect The intention of the
> original code
> was to ensure reported counters are always correct, but it did not work
> (because at query
> time, the peer in kernel is already gone, so we only got an error message) -
> and very
> inefficiently so (because we queried all the peers all the time).
> End-of-session final counter
> values will be implemented properly by a followup patch leveraging counters
> piggybacked on the
> kernel's "DEL_PEER" notification message.
> * p2mp server: improve handling of mbuf lists in the face of broadcast or
> multicast traffic,
> and fix a bug on client exit that could lead to a server queue deadlock in
> very particular
> scenarios.
>
> Windows MSI changes since 2.7.7-I001:
>
> * Update included dco-win driver to v2.8.13
> * CVE-2026-105390 - a locking flaw allowed a local user with access to the
> driver's device
> to cause a system deadlock and denial of service, hanging the host until it
> was
> power-cycled.
> * Performance improvements by moving to multi-core data processing.
> * See <https://github.com/OpenVPN/ovpn-dco-win/releases/tag/2.8.13>
> https://github.com/OpenVPN/ovpn-dco-win/releases/tag/2.8.13%3E for details.
> * Update included OpenSSL to 3.6.5
> * Update included Easy-RSA to 3.2.7
>
> More details can be found in the Changes document:
>
> <https://github.com/OpenVPN/openvpn/blob/v2.7.8/Changes.rst>
> https://github.com/OpenVPN/openvpn/blob/v2.7.8/Changes.rst%3E
>
> Source code and Windows installers can be downloaded from our download page:
>
> <https://openvpn.net/community/> https://openvpn.net/community/%3E
>
> Packages for Debian, Ubuntu, Fedora, RHEL, and openSUSE are available in the
> various
> official Community repositories:
>
> <https://community.openvpn.net/Pages/OpenVPN%20software%20repos>
> https://community.openvpn.net/Pages/OpenVPN%20software%20repos%3E
>
> Kind regards,
> --
> Frank Lichtenheld
>
> _______________________________________________
> Openvpn-users mailing list
> [email protected]
> mailto:[email protected]
> https://lists.sourceforge.net/lists/listinfo/openvpn-users
>
--
Simon Matter Tel: +41 61 311 40 70
Glasiweg 8b
CH-6242 Wauwil
_______________________________________________
Openvpn-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-users