SB20250630109 - Local denial of service in OpenVPN ovpn-dco-win driver
Published: June 30, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2025-50054)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error. A local user can send a very large control message buffer to the kernel driver, trigger memory corruption and perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.