Buffer Overflow in OpenVPN DCO for Windows Affects Local Systems
CVE-2026-2738
5.6MEDIUM
What is CVE-2026-2738?
A buffer overflow vulnerability in the ovpn-dco-win version 2.8.0 allows local attackers to manipulate packet sizes, leading to potential system crashes. Specifically, this vulnerability can be exploited by sending oversized packets to the remote peer, particularly when the AEAD tag appears at the end of the encrypted packet, posing serious risks to network reliability and security.
Affected Version(s)
ovpn-dco-win Windows 2.8.0