Blame
| f9af5c | flichtenheld | 2026-10-07 14:13:37 | 1 | # CVE-2026-105390 - ovpn-dco-win: unprivileged local DoS - device lock held across socket send deadlocks the host |
| 2 | ||||
| 3 | Improper synchronization in the OpenVPN ovpn-dco-win driver for Windows allows local attackers to trigger a deadlock |
|||
| 4 | via a crafted write to the ovpn-dco device, causing the host to become unresponsive. |
|||
| 5 | ||||
| 6 | ovpn-dco-win driver for Windows version 0.6.5 through 1.3.3 and 2.4.0 through 2.8.7 are affected. This is fixed in versions 1.3.4 and 2.8.13. |
|||
| 7 | ||||
| 8 | A fixed driver is contained in OpenVPN Windows installer packages for 2.7.8. |
|||
| 9 | ||||
| 1766ee | flichtenheld | 2026-10-07 14:14:18 | 10 | CVE Record: [CVE-2026-105390](https://www.cve.org/CVERecord?id=CVE-2026-105390) |
| f9af5c | flichtenheld | 2026-10-07 14:13:37 | 11 | |
| 12 | Release notes: |
|||
| 13 | * [ovpn-dco-win-2.8.13](https://github.com/OpenVPN/ovpn-dco-win/releases/tag/2.8.13) |
|||
| 14 | * [ovpn-dco-win-1.3.4](https://github.com/OpenVPN/ovpn-dco-win/releases/tag/1.3.4) |
|||
| 15 | ||||
| 16 | Reported-By: Found internally |
