OpenVPN 2.7.8 Released with Certificate and Windows Security Fixes

OpenVPN 2.7.8 is out with fixes for three security vulnerabilities, along with DCO, certificate validation, and server reliability improvements.

OpenVPN 2.7.8 has been released with fixes for three security vulnerabilities, along with several DCO and server reliability improvements.

The first issue, CVE-2026-84790, affects certificate handling. OpenVPN now rejects certificates with subject fields containing embedded NULL bytes. This makes validation stricter on OpenSSL-based builds. mbedTLS already rejected such certificates.

CVE-2026-88964 fixes an unsigned underflow that could occur when clearing the domain_search_list option. CVE-2026-84256 addresses a Windows-specific issue where cmd.exe could expand variables inside quoted arguments.

The release also fixes a tls-crypt-v2 client-side problem where OpenVPN could attempt to add a wrapped client key without having valid key material. No CVE was assigned to that issue.

On the DCO side, OpenVPN 2.7.8 fixes stale iroutes, Linux Netlink race conditions, and errors during peer or key setup. These errors could previously terminate the whole server process instead of only the affected client instance.

Other fixes include more consistent certificate handling between OpenSSL and mbedTLS, better handling of invalid pushed cipher configurations, and a rare point-to-multipoint server queue deadlock.

For more details, see the changelog.

Bobby Borisov

Bobby Borisov

Bobby, an editor-in-chief at Linuxiac, is a Linux professional with over 20 years of experience. With a strong focus on Linux and open-source software, he has worked as a Senior Linux System Administrator, Software Developer, and DevOps Engineer for small and large multinational companies.

Leave a Reply

Your email address will not be published. Required fields are marked *