Buffer Overflow Vulnerability in OpenVPN Software
CVE-2026-11604
5.6MEDIUM
What is CVE-2026-11604?
The OpenVPN Software, specifically the ovpn-dco-win version 2.0.0 through 2.8.3, contains a vulnerability due to improper calculation of buffer sizes in its epoch key generator. This flaw can be exploited by a remote authenticated peer who sends specially crafted data packets, leading to a heap-based buffer overflow and potential memory corruption within the kernel. If successfully executed, this could result in a system crash, effectively causing a denial of service.
Affected Version(s)
ovpn-dco-win Windows 2.0.0 <= 2.5.8