Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 11 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Jun 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Heap Buffer Overflow in OpenVPN ovpn-dco-win Leading to System Crash | |
| First Time appeared |
Openvpn
Openvpn ovpn-dco-win |
|
| Vendors & Products |
Openvpn
Openvpn ovpn-dco-win |
Wed, 10 Jun 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to trigger a heap-based buffer overflow and kernel memory corruption via a crafted data packet, resulting in a system crash (denial of service). | |
| Weaknesses | CWE-122 CWE-131 CWE-787 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: OpenVPN
Published:
Updated: 2026-06-11T13:27:17.336Z
Reserved: 2026-06-08T15:19:28.369Z
Link: CVE-2026-11604
Updated: 2026-06-11T13:27:03.764Z
Status : Awaiting Analysis
Published: 2026-06-10T22:16:55.643
Modified: 2026-06-11T15:21:30.653
Link: CVE-2026-11604
No data.
OpenCVE Enrichment
Updated: 2026-06-10T22:30:22Z