Medium severity6.5NVD Advisory· Published Jun 10, 2026· Updated Aug 11, 2026
CVE-2026-11604
CVE-2026-11604
Description
An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to trigger a heap-based buffer overflow and kernel memory corruption via a crafted data packet, resulting in a system crash (denial of service).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3(expand)+ 1 more
- (no CPE)
- (no CPE)range: >=2.0.0 <=2.8.3
Patches
Vulnerability mechanics
References
2- community.openvpn.net/Security%20Announcements/CVE-2026-11604nvdVendor Advisory
- github.com/OpenVPN/ovpn-dco-win/releasesnvdRelease Notes
News mentions
0No linked articles in our index yet.