CVE-2026-105390 - ovpn-dco-win: unprivileged local DoS - device lock held across socket send deadlocks the host

Improper synchronization in the OpenVPN ovpn-dco-win driver for Windows allows local attackers to trigger a deadlock via a crafted write to the ovpn-dco device, causing the host to become unresponsive.

ovpn-dco-win driver for Windows version 0.6.5 through 1.3.3 and 2.4.0 through 2.8.7 are affected. This is fixed in versions 1.3.4 and 2.8.13.

A fixed driver is contained in OpenVPN Windows installer packages for 2.7.8.

CVE Record: CVE-2026-105390

Release notes:

Reported-By: Found internally

0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9