ELSEIF
Your brief EB
525 stories from 214 feeds 1270 clusters Refreshed 12 minutes ago next pull 21:07

SECURITY Signal 56

OpenVPN 2.7.7 patches seven CVEs, adds Linux Netlink validation, and reduces EPOCH key retention

OpenVPN 2.7.7 resolves seven CVE-tracked vulnerabilities, including Windows buffer overreads and command-line quoting issues, while adding Linux Netlink validation and reducing EPOCH key retention.

WHY IT MATTERS

Administrators running OpenVPN on Windows should prioritize this update to close several local privilege and integrity vectors, including configuration path handling and NULL DACL assignments. The release also improves packet processing performance by avoiding unnecessary HMAC key resets and reducing EPOCH future key retention.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

OpenVPN 2.7.7 resolves seven CVE-tracked vulnerabilities, including a buffer overread in openvpnserv and an off-by-one error in write_dhcp_search_str().

02

The Linux client now validates Netlink replies against the requests that generated them to harden kernel communication.

03

OpenVPN reduces EPOCH future key retention from 16 to 4 and stops resetting the HMAC key for every packet.

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
Linuxiac OpenVPN 2.7.7 Released with Seven Security Fixes Open ↗