VYPR
Medium severity6.5NVD Advisory· Published Jun 10, 2026· Updated Aug 11, 2026

CVE-2026-11604

CVE-2026-11604

Description

An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to trigger a heap-based buffer overflow and kernel memory corruption via a crafted data packet, resulting in a system crash (denial of service).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:openvpn:openvpn:*:*:*:*:*:*:*:*
    Range: >=2.0.0,<=2.8.3
  • OpenVPN/Ovpn Dco Winreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: >=2.0.0 <=2.8.3

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.