CVE-2026-11604: Buffer Overflow
An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to trigger a heap-based buffer overflow and kernel memory corruption via a crafted data packet, resulting in a system crash (denial of service).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
OpenVPN ovpn-dco-winfrom your environment.Uninstall ovpn-dco-win (OpenVPN Data Channel Offload for Windows) if it is not required to eliminate exposure to the vulnerable component (versions 2.0.0 through 2.8.3).
- Compensating control
Restrict which remote peers can connect to the affected OpenVPN endpoint (for example via firewall rules, ACLs, or VPN server configuration) to only trusted/managed peers to reduce the risk of a remote authenticated peer sending crafted packets that trigger the vulnerability.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11604?
CVE-2026-11604 has a risk rating of 56, indicating a moderate severity level.
How do I fix CVE-2026-11604?
To mitigate CVE-2026-11604, upgrade OpenVPN ovpn-dco-win to version 2.8.4 or later.
What impact does CVE-2026-11604 have on my system?
CVE-2026-11604 may lead to a denial of service by causing system crashes due to a heap-based buffer overflow.
Who is affected by CVE-2026-11604?
CVE-2026-11604 affects users of OpenVPN ovpn-dco-win versions 2.0.0 through 2.8.3.
What type of vulnerability is CVE-2026-11604?
CVE-2026-11604 is classified as a Buffer Overflow vulnerability.