CVE-2026-11604
An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to trigger a heap-based buffer overflow and kernel memory corruption via a crafted data packet, resulting in a system crash (denial of service).
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.6
- CVSS vector
- CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
- EPSS probability
- 0.34%
- CWE
- CWE-131, CWE-122, CWE-787
- Published
- 2026-06-10
- Last modified
- 2026-06-11
Affected products
- OpenVPN ovpn-dco-win
Weakness type
Related vulnerabilities
- CVE-2026-22590 — Fast-DDS Discovery Server: Out-of-Bounds Read & Heap Memory Disclosure via DATA_FRAG sampleSize / fragmentsInSubmessage
- CVE-2026-69598 — Windows iSCSI Remote Code Execution Vulnerability
- CVE-2026-78221 — An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1...
- CVE-2026-18743 — Popt-devel: popt-static: short realloc in poptconfigfiletostring
- CVE-2026-78002 — Rsyslog: rsyslog: denial of service via heap buffer overflow in rainerscript replace() function
- CVE-2026-44254 — Wazuh: Stack Out-of-Bounds Write in remoted Decompression Path
- CVE-2026-52834 — jxl-oxide: Out-of-bounds writes due to integer overflow in jxl-grid on 32-bit platforms
- CVE-2026-75093 — sonos tract ONNX Initializer Loader tensor.rs from_raw_dt_align buffer size