An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to trigger a heap-based buffer overflow and kernel memory corruption via a crafted data packet, resulting in a system crash (denial of service).
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 10 Jun 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Heap Buffer Overflow in OpenVPN ovpn-dco-win Leading to System Crash | |
| First Time appeared |
Openvpn
Openvpn ovpn-dco-win |
|
| Vendors & Products |
Openvpn
Openvpn ovpn-dco-win |
Wed, 10 Jun 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to trigger a heap-based buffer overflow and kernel memory corruption via a crafted data packet, resulting in a system crash (denial of service). | |
| Weaknesses | CWE-122 CWE-131 CWE-787 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: OpenVPN
Published:
Updated: 2026-06-10T21:04:37.141Z
Reserved: 2026-06-08T15:19:28.369Z
Link: CVE-2026-11604
No data.
Status : Received
Published: 2026-06-10T22:16:55.643
Modified: 2026-06-10T22:16:55.643
Link: CVE-2026-11604
No data.
OpenCVE Enrichment
Updated: 2026-06-10T22:30:22Z