CVE-2026-82325 - Windows dco-win use-after-free in multipeer peer table handling

The ovpn-dco-win driver keys its secondary peer tables by transport and VPN address rather than by peer identity, and neither insertion nor deletion accounted for that. A failed insertion left a peer partially indexed without rollback, and deletion removed whatever entry matched the key - not necessarily the peer being deleted - while releasing the peer it was passed regardless. The reference count could therefore drop below zero, and the underflow was treated as another reason to free the peer, so a peer could be freed while it was still referenced.

ovpn-dco-win driver version 2.5.0 through 2.8.6 are affected. This is fixed in driver version 2.8.7, which is shipped with the OpenVPN 2.7.7-I001 Windows installers.

CVE Record: CVE-2026-82325

Github:

Release notes:

Reported-By: Okan Kurtulus

0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9