Description
An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to trigger a heap-based buffer overflow and kernel memory corruption via a crafted data packet, resulting in a system crash (denial of service).
Published: 2026-06-10
Score: 5.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 11 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 10 Jun 2026 22:45:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in OpenVPN ovpn-dco-win Leading to System Crash
First Time appeared Openvpn
Openvpn ovpn-dco-win
Vendors & Products Openvpn
Openvpn ovpn-dco-win

Wed, 10 Jun 2026 21:45:00 +0000

Type Values Removed Values Added
Description An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to trigger a heap-based buffer overflow and kernel memory corruption via a crafted data packet, resulting in a system crash (denial of service).
Weaknesses CWE-122
CWE-131
CWE-787
References
Metrics cvssV4_0

{'score': 5.6, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}


Subscriptions

Openvpn Ovpn-dco-win
cve-icon MITRE

Status: PUBLISHED

Assigner: OpenVPN

Published:

Updated: 2026-06-11T13:27:17.336Z

Reserved: 2026-06-08T15:19:28.369Z

Link: CVE-2026-11604

cve-icon Vulnrichment

Updated: 2026-06-11T13:27:03.764Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-10T22:16:55.643

Modified: 2026-06-11T15:21:30.653

Link: CVE-2026-11604

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-10T22:30:22Z

Weaknesses