CVE-2026-2738
Received
Received - Intake
Buffer Overflow in ovpn-dco-win 2.8.0 Causes System Crash
Publication date: 2026-02-19
Last updated on: 2026-02-19
Assigner: OpenVPN Inc.
Description
Description
Buffer overflow in ovpn‑dco‑win version 2.8.0 allows local attackers to cause a system crash by sending too large packets to the remote peer when the AEAD tag appears at the end of the encrypted packet
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| openvpn | ovpn-dco-win | 2.8.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-131 | The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow. |