OpenVPN 2.7.8 Released: Security Hardening for Certificates, TLS, and Kernel Data Channel

Published by

OpenVPN 2.7.8 has been released as a maintenance update focusing on security hardening, particularly for multi-client servers and kernel-accelerated Data Channel Offload (DCO) paths, addressing four notable security vulnerabilities, three of which have CVE identifiers. The release, which includes stability improvements such as the ability to restart individual server instances instead of crashing the entire server on peer failure, is critical for operators managing large deployments. Key fixes involve handling NULL bytes in certificate subjects, preventing unsigned integer underflows, and reinforcing command-line quoting in Windows to prevent potential attacks. Users are encouraged to upgrade, especially those using multi-client servers or DCO setups, and to ensure that their entire software stack remains compatible with the new version to maximize security benefits



OpenVPN 2.7.8 Released: Security Hardening for Certificates, TLS, and Kernel Data Channel

OpenVPN 2.7.8 shipped as a targeted maintenance release, delivering four security fixes aimed at multi-client servers and kernel-accelerated DCO paths. Three of the fixes carry CVE identifiers, covering NULL bytes in certificates (CVE-2026-84790), an unsigned underflow in the domain search list (CVE-2026-88964), and Windows cmd.exe quoting (CVE-2026-84256), with a fourth tls-crypt-v2 change left unassigned on policy grounds. Beyond security, the update adds stability wins like restarting individual instances instead of crashing the whole server when a peer fails, plus uniform duplicate-certificate handling across OpenSSL and mbedTLS. Operators running large servers should upgrade, since most fixes target the exact code paths that break under load.

OpenVPN 2.7.8 Released: Security Hardening for Certificates, TLS, and Kernel Data Channel @ Linux Compatible