CVE-2025-50054 - Buffer overflow in OpenVPN ovpn-dco-win version 1.3.0 and earlier and version 2.5.8 and earlier

Buffer overflow in OpenVPN ovpn-dco-win version 1.3.0 and earlier and version 2.5.8 and earlier allows a local user process to send a too large control message buffer to the kernel driver resulting in a system crash

The Windows DCO driver will crash when the user space process sends a control packet larger than 1500 bytes. It does not look like this could be triggered remotely, but definitely locally. And most importantly, even by unprivileged processes talking to the Windows DCO driver. OpenVPN itself won’t send such large messages because it has a built-in length limit. But any custom-compiled OpenVPN that ignores that limit, or any other process that talks to the Windows DCO driver and sends such large packets, can trigger it.

OpenVPN GUI for Windows version 2.6.0-I005 through 2.6.14-I001 and version 2.7_alpha1-I001 are affected. This is fixed in version 2.6.14-I002 and version 2.7_alpha2-I001.

Release notes: openvpn-2.7_alpha2

CVE Record: https://www.cve.org/CVERecord?id=CVE-2025-50054

0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9