---
id: CVE-2026-11604
title: >-
  An incorrect buffer size calculation in the epoch key generator in OpenVPN
  ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to
  trigger a heap-based buffer overflow and kernel memory corruption via a
  crafted dat…
summary: >-
  An incorrect buffer size calculation in the epoch key generator in OpenVPN
  ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to
  trigger a heap-based buffer overflow and kernel memory corruption via a
  crafted dat…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-122
  - CWE-131
  - CWE-787
vendor: openvpn
product: ovpn-dco-win
affected:
  - 'ovpn-dco-win >= 2.0.0, <= 2.8.3'
published: '2026-06-10'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T14:39:22.383'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-11604'
references:
  - url: 'https://community.openvpn.net/Security%20Announcements/CVE-2026-11604'
    label: security@openvpn.net
  - url: 'https://github.com/OpenVPN/ovpn-dco-win/releases'
    label: security@openvpn.net
tags:
  - nvd
epss: 0.00338
epssPercentile: 0.24429
ingestedAt: '2026-09-24T14:44:21.301Z'
---

## Overview

An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to trigger a heap-based buffer overflow and kernel memory corruption via a crafted data packet, resulting in a system crash (denial of service).

## Affected

- `ovpn-dco-win >= 2.0.0, <= 2.8.3`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
