SECURITY Signal 56
OpenVPN 2.7.7 patches seven CVEs, adds Linux Netlink validation, and reduces EPOCH key retention
OpenVPN 2.7.7 resolves seven CVE-tracked vulnerabilities, including Windows buffer overreads and command-line quoting issues, while adding Linux Netlink validation and reducing EPOCH key retention.
Administrators running OpenVPN on Windows should prioritize this update to close several local privilege and integrity vectors, including configuration path handling and NULL DACL assignments. The release also improves packet processing performance by avoiding unnecessary HMAC key resets and reducing EPOCH future key retention.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
OpenVPN 2.7.7 resolves seven CVE-tracked vulnerabilities, including a buffer overread in openvpnserv and an off-by-one error in write_dhcp_search_str().
The Linux client now validates Netlink replies against the requests that generated them to harden kernel communication.
OpenVPN reduces EPOCH future key retention from 16 to 4 and stops resetting the HMAC key for every packet.
THE CLUSTER
↗