From: Adolf Belka <adolf.belka@ipfire.org>
To: development@lists.ipfire.org
Cc: Adolf Belka <adolf.belka@ipfire.org>
Subject: [PATCH] openvpn: Update to version 2.7.7
Date: Sun, 13 Sep 2026 19:12:23 +0200 [thread overview]
Message-ID: <20260913171230.3920551-24-adolf.belka@ipfire.org> (raw)
In-Reply-To: <20260913171230.3920551-1-adolf.belka@ipfire.org>
- Update from version 2.7.6 to 2.7.7
- No change in rootfile
- 10 CVE fixes
- Changelog
2.7.7
Security fixes
reliability layer: Avoid unbounded reliable TLS timeout (CVE-2026-84732)
reliability layer: Ignore acks for packets that cannot be outstanding
(CVE-2026-84732)
(both reliability layer bugs found by Mark Bregman <mark.bregman@fox-it.com>,
tracked in Github: OpenVPN/openvpn-private-issues#161)
Windows: fix CreateProcess() command line quoting for characters that are special
to cmd.exe and where a combination of validation script plus rogue CA could
lead to misbehavior (CVE-2026-84256)
(Bug found by Clouditera Security <security@clouditera.com>, tracked
in Github: OpenVPN/openvpn-private-issues#159)
Windows: fix tapctl to always call netsh.exe with full path (as we do elsewhere)
(CVE-2026-84226)
(Bug found by BreachX Zero Day Labs, using Typhon AI Mil v2, tracked
in Github: OpenVPN/openvpn-private-issues#164)
Windows: don't use NULL DACL with system objects, namely the --service exit event
and the netsh.exe guard semaphore. The old approach was prone to a local DoS
where one user could interfere with other users' openvpn processes by
blocking the netsh semaphore or sending events. This only affects setups not
using the iservice, or using the automatic service to start/stop openvpn
(CVE-2026-82312).
(Bug found by DEBRAJ BASAK <https://in.linkedin.com/in/debrajbasak>,
tracked in Github: OpenVPN/openvpn-private-issues#167)
Linux Netlink: validate netlink replies against the request
(Suggested by Joshua Rogers <contact@joshua.hu> as a security improvement,
tracked in Github: OpenVPN/openvpn-private-issues#9)
Windows: fix off-by-one on input validation in openvpnserv (discovered while
fixing CVE-2026-78221)
Windows: openvpnserv: pass correct NRPT domains size - when IDN domains with
UTF8 encoding were involved, a buffer overread could be achieved (CVE-2026-78221).
(Bug found by BreachX Zero Day Labs, using Typhon AI Mil v2,
in Github: OpenVPN/openvpn-private-issues#162)
Windows: harden CheckConfigPath() a bit more (another improvement while working
on CVE-2026-78043)
Windows: openvpnserv: don't allow '/' in config paths (the APIs windows uses for
path validation do not handle '/' as path
separator, while the file open APIs do, so this could be used to circumvent
our config path validation, leading to openvpn.exe starting a user-controlled
config file even if administatively not allowed. CVE-2026-78043)
(Bug found by BreachX Zero Day Labs, using Typhon AI Mil v2,
in Github: OpenVPN/openvpn-private-issues#162)
Windows: dhcp: Fix off-by-one in write_dhcp_search_str() temp buffer guard
(suitable DHCP options could lead to a single-byte overflow of a temp
buffer, CVE-2026-81738)
(Bug found by Andre Kropp (Nexory) and ChinhNguyen, tracked
in Github: OpenVPN/openvpn-private-issues#165)
Bugfixes
work around a pubkey-handling bug in mbedTLS 4.1.0 and 4.2.0 (supposedly fixed
in 4.3.0)
multi: don't let stale-routes-check delete permanent routes (the
--stale-routes-check did not delete dynamic cached routes,
but also routes installed by --iroute and --ifconfig-push - fix by
introducing route flags and restraining the check on them)
(Github: #1063)
Windows: openvpnserv: fix log lines format string interface names with
international characters printed in some error messages need to be converted
from UTF8 to UCS16 first.
clinat: do not adjust UDP checksum if zero (as per RFC768) (Github: #1037)
OpenSSL: avoid resetting the HMAC key on every packet (Github: #1088)
fix format string specifier for size_t (%zu)
ssl: Do not queue control ciphertext while a packet is still queued (fixes
problems in TCP p2p handshake when both sides try to handshake
at the same time)
(Github: #1089)
Reenable xmit_hold when using p2p tcp-server and tls-server (in TCP server mode,
the server is not expected to initiate the TLS
handshake - bug introduced by the multisocket code, checking the wrong
variable for socket protocol)
(Github: #1089)
fix test_misc compile issues with -Werror
User-visible Changes
when using EPOCH data channel format, reduce number of future keys from 16 to 4
(calculation was wrong, 4 spare keys are sufficient for 100+ Gbit/s links,
less log spam in userland and less resources used in in-kernel implementations)
Building/Testing improvements
clang-format: Convert deprecated setting KeepEmptyLinesAtTheStartOfBlocks
t_client.sh: various improvements
Documentation improvements
doc: Update doxygen references to removed tunnel_server_{udp, tcp}() (those
functions do not exist in 2.7+ anymore)
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
lfs/openvpn | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/lfs/openvpn b/lfs/openvpn
index 010c3a375..266dc7140 100644
--- a/lfs/openvpn
+++ b/lfs/openvpn
@@ -24,7 +24,7 @@
include Config
-VER = 2.7.6
+VER = 2.7.7
THISAPP = openvpn-$(VER)
DL_FILE = $(THISAPP).tar.gz
@@ -40,7 +40,7 @@ objects = $(DL_FILE)
$(DL_FILE) = $(DL_FROM)/$(DL_FILE)
-$(DL_FILE)_BLAKE2 = 0cf4f6c7337ef3e31cb6f261423863b86fedcaaa69272d26811f4066afcece873ccebca167cb5e9f37bc474ccbbad7f71effc0678b98ed52864a96351a8cc3f0
+$(DL_FILE)_BLAKE2 = 6f4230df1f238f0b0e1bdcc978850cf3f49c8c61dcebcdc819861399bf68016d14800140a2fb69bfc7fdc8fa4987cde531d59249f3f91533d7c9244080d557fc
install : $(TARGET)
--
2.55.0
next prev parent reply other threads:[~2026-09-13 17:12 UTC|newest]
Thread overview: 31+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-13 17:12 [PATCH] core205: Ship curl Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship iana-etc Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship jansson Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship libksba Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship libpcap Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship liburcu Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship libxml2 Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship pcre2 Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship tzdata Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship util-linux Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship vim Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship xz Adolf Belka
2026-09-13 17:12 ` [PATCH] curl: Update to version 8.22.0 Adolf Belka
2026-09-13 17:12 ` [PATCH] fetchmail: Update to version 6.6.7 Adolf Belka
2026-09-13 17:12 ` [PATCH] frr: Update to version 10.7.1 Adolf Belka
2026-09-13 17:12 ` [PATCH] hwdata: Update to version 0.411 Adolf Belka
2026-09-13 17:12 ` [PATCH] iana-etc: Update to version 20260911 Adolf Belka
2026-09-13 17:12 ` [PATCH] jansson: Update to version 2.15.1 Adolf Belka
2026-09-13 17:12 ` [PATCH] libcap-ng: Update to version 0.9.6 Adolf Belka
2026-09-13 17:12 ` [PATCH] libksba: Update to version 1.8.1 Adolf Belka
2026-09-13 17:12 ` [PATCH] libpcap: Update to version 1.10.7 Adolf Belka
2026-09-13 17:12 ` [PATCH] liburcu: Update to version 0.15.7 Adolf Belka
2026-09-13 17:12 ` [PATCH] libxml2: Update to version 2.15.4 Adolf Belka
2026-09-13 17:12 ` Adolf Belka [this message]
2026-09-13 17:12 ` [PATCH] pcre2: Update to version 10.48 Adolf Belka
2026-09-13 17:12 ` [PATCH] postfix: Update to version 3.11.7 Adolf Belka
2026-09-13 17:12 ` [PATCH] systemd: Update to version 261.3 Adolf Belka
2026-09-13 17:12 ` [PATCH] tzdata: Update to version 2026d Adolf Belka
2026-09-13 17:12 ` [PATCH] util-linux: Update to version 2.42.3 Adolf Belka
2026-09-13 17:12 ` [PATCH] vim: Update to version 9.2.1091 Adolf Belka
2026-09-13 17:12 ` [PATCH] xz: Update to version 5.8.4 Adolf Belka
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260913171230.3920551-24-adolf.belka@ipfire.org \
--to=adolf.belka@ipfire.org \
--cc=development@lists.ipfire.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox