Blame
| 40026d | uddr | 2026-09-07 10:02:29 | 1 | # CVE-2026-82325 - Windows dco-win use-after-free in multipeer peer table handling |
| 2 | ||||
| 3 | The ovpn-dco-win driver keys its secondary peer tables by transport and VPN address rather than by peer identity, and neither insertion nor deletion accounted for that. A failed insertion left a peer partially indexed without rollback, and deletion removed whatever entry matched the key - not necessarily the peer being deleted - while releasing the peer it was passed regardless. The reference count could therefore drop below zero, and the underflow was treated as another reason to free the peer, so a peer could be freed while it was still referenced. |
|||
| 4 | ||||
| 5 | ovpn-dco-win driver version 2.5.0 through 2.8.6 are affected. This is fixed in driver version 2.8.7, which is shipped with the OpenVPN 2.7.7-I001 Windows installers. |
|||
| 6 | ||||
| 7 | CVE Record: [CVE-2026-82325](https://www.cve.org/CVERecord?id=CVE-2026-82325) |
|||
| 8 | ||||
| 9 | Github: |
|||
| 10 | * [OpenVPN/ovpn-dco-win-private#8](https://github.com/OpenVPN/ovpn-dco-win-private/issues/8) |
|||
| 11 | * [OpenVPN/ovpn-dco-win#140](https://github.com/OpenVPN/ovpn-dco-win/pull/140) |
|||
| 12 | ||||
| 13 | Release notes: |
|||
| 14 | * [openvpn-2.7.7](https://community.openvpn.net/ReleaseHistory#openvpn-277-released-3-september-2026) |
|||
| 15 | ||||
| 16 | Reported-By: Okan Kurtulus |
