Abstrakter Code als Symbol fuer eine Sicherheitsluecke

OpenVPN 2.7.7 Patches Seven Security Flaws

The OpenVPN project shipped version 2.7.7 on 3 September 2026. The maintenance release closes seven CVE-tracked security vulnerabilities, hardens Netlink communication on Linux and fixes several networking bugs.

Five of seven flaws hit Windows

The bulk of the fixes target Windows components. CVE-2026-82312 concerned system objects created with a NULL DACL – on Windows that does not mean “no access” but unrestricted access for every local user. The release also corrects faulty command-line quoting in CreateProcess() (CVE-2026-84256), a flaw in the tapctl helper utility (CVE-2026-84226), and two issues in the openvpnserv service: a buffer overread with internationalized domain names (CVE-2026-78221) and a bypassed path validation (CVE-2026-78043).

Platform-independent fixes and Netlink hardening

Two vulnerabilities are platform-independent: CVE-2026-84732 addresses two problems in OpenVPN’s reliability layer, while CVE-2026-81738 fixes an off-by-one error in write_dhcp_search_str(). As an additional safeguard, the Linux client now validates Netlink replies against the originating request – a hardening measure suggested by Joshua Rogers to guard against forged kernel responses.

The project classifies 2.7.7 as a bugfix release addressing several security issues. All platforms are affected, but the update is most pressing for Windows installations. Users are advised to upgrade to 2.7.7 promptly.

Sources: OpenVPN Community Wiki · OpenVPN Security Advisories · Linuxiac

Mastodon
Scroll to Top