Blame

e13ea9 David Sommerseth 2026-02-19 12:40:27 1
# CVE-2026-2738
2
a69b4c David Sommerseth 2026-02-19 19:45:05 3
The ovpn-dco-win version 2.8.0 has a flaw which appears when connecting to an OpenVPN 2.7.0 server, or other implementations with data epoch keys support. This moved the AEAD tag towards the end of the encrypted packet. In the ovpn-dco-win version 2.8.0, the calculated buffer length did not account for the needed buffer overhead to add the AEAD tag, which resulted in a buffer overflow.
4
5
The ovpn-dco-win version 2.8.0 was shipped with OpenVPN version 2.7_beta3 through 2.7.0_I016. The OpenVPN 2.7.0_I017 Windows installer provides ovpn-dco-win version 2.8.2 which resolves this issue.
6
7
CVE record: https://www.cve.org/CVERecord?id=CVE-2026-2738 <br/>GitHub ovpn-dco-win issue: https://github.com/OpenVPN/ovpn-dco-win/issues/130<br/>GitHub ovpn-dco-win release: https://github.com/OpenVPN/ovpn-dco-win/releases/tag/2.8.2<br/>OpenVPN 2.7.0_I017 release: https://community.openvpn.net/Downloads#openvpn-270-released-11-february-2026