CVE-2026-2738

The ovpn-dco-win version 2.8.0 has a flaw which appears when connecting to an OpenVPN 2.7.0 server, or other implementations with data epoch keys support. This moved the AEAD tag towards the end of the encrypted packet. In the ovpn-dco-win version 2.8.0, the calculated buffer length did not account for the needed buffer overhead to add the AEAD tag, which resulted in a buffer overflow.

The ovpn-dco-win version 2.8.0 was shipped with OpenVPN version 2.7_beta3 through 2.7.0_I016. The OpenVPN 2.7.0_I017 Windows installer provides ovpn-dco-win version 2.8.2 which resolves this issue.

CVE record: https://www.cve.org/CVERecord?id=CVE-2026-2738
GitHub ovpn-dco-win issue: https://github.com/OpenVPN/ovpn-dco-win/issues/130
GitHub ovpn-dco-win release: https://github.com/OpenVPN/ovpn-dco-win/releases/tag/2.8.2
OpenVPN 2.7.0_I017 release: https://community.openvpn.net/Downloads#openvpn-270-released-11-february-2026

On this page
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9