Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    OpenVPN Race Condition Remediation

    Scheduled Pinned Locked Moved Messages from the pfSense Team
    8 Posts 5 Posters 1.0k Views 5 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P Offline
      pfGeorge Netgate
      last edited by

      At the end of April, OpenVPN® announced CVE-2026-40215, a race condition vulnerability in the TLS handshake process that could lead to packet data leakage from a previous handshake under specific circumstances. This vulnerability affects OpenVPN versions 2.6.0 through 2.6.19. pfSense® Plus version 26.03 shipped with OpenVPN version 2.6.16, which contains this vulnerability.

      To address this issue, Netgate® has released OpenVPN version 2.6.20 to pfSense Plus repositories. Follow the steps below to update your OpenVPN installation.

      Update Instructions

      Option 1: SSH or Console

      1. Log in to your pfSense Plus instance using the root account

      2. Select option 8 from the menu to open a shell

      3. Execute the following command:

        pkg upgrade -y

      4. Once the upgrade completes, log in to the webGUI and navigate to Status > Services

      5. Click the Restart button for each running OpenVPN instance

      Option 2: WebGUI

      1. Log in to your pfSense Plus instance using the root account

      2. Navigate to Diagnostics > Command Prompt

      3. Enter the following command:

        pkg upgrade -y

      4. Once the upgrade completes, navigate to Status > Services

      5. Click the Restart button for each running OpenVPN instance

      Verification

      After completing these steps, your pfSense Plus instance will be patched against CVE-2026-40215. No further action is required.

      Note: If you have not yet installed or upgraded to pfSense Plus version 26.03, this patch will be automatically included when you install or upgrade.

      1 Reply Last reply Reply Quote 5
      • P pfGeorge pinned this topic on
      • SteveITSS SteveITS referenced this topic
      • GertjanG Gertjan referenced this topic
      • S Offline
        slu
        last edited by

        @pfGeorge my pfSense+ boxes are updated, any change to fix this also von 2.8.1?

        pfSense Gold subscription

        1 Reply Last reply Reply Quote 0
        • P Offline
          pandtech
          last edited by

          Thanks for the clear write-up and step‑by‑step instructions. Updates like this are easy to miss in smaller environments, so having the exact commands and restart steps laid out for patching OpenVPN on pfSense Plus really helps avoid unnecessary risk.

          1 Reply Last reply Reply Quote 0
          • S Offline
            slu
            last edited by

            @pfGeorge any update for 2.8.1?

            pfSense Gold subscription

            1 Reply Last reply Reply Quote 0
            • stephenw10S Online
              stephenw10 Netgate Administrator
              last edited by

              This is available in the 2.8.1 repo now.

              S D 2 Replies Last reply Reply Quote 4
              • S Offline
                slu @stephenw10
                last edited by

                @stephenw10 yes, I can confirm that, thank you.

                Installed packages to be UPGRADED:
                	openvpn: 2.6.16 -> 2.6.20 [pfSense]
                
                Installed packages to be REINSTALLED:
                	pfSense-pkg-openvpn-client-export-1.9.13 [pfSense]
                

                pfSense Gold subscription

                1 Reply Last reply Reply Quote 1
                • D Offline
                  Darkk @stephenw10
                  last edited by

                  @stephenw10 Yep. You can also check it via diganostic and execute in command:

                  openvpn --version

                  The output should show version 2.6.20 or higher

                  If not you can run pkg upgrade -y openvpn

                  Several of my pfsense 2.8.1 instances already updated themselves. I had to manually update one.

                  S 1 Reply Last reply Reply Quote 0
                  • S Offline
                    slu @Darkk
                    last edited by

                    @Darkk said in OpenVPN Race Condition Remediation:

                    Several of my pfsense 2.8.1 instances already updated themselves.

                    Reinstall openvpn-client-export update it also.

                    pfSense Gold subscription

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.