Heap-based buffer overflow in OpenVPN Data Channel Offload driver for Windows - CVE-2026-2738

 

Heap-based buffer overflow in OpenVPN Data Channel Offload driver for Windows - CVE-2026-2738

Published: April 24, 2026


Vulnerability identifier: #VU127530
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-2738
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to a heap-based buffer overflow in the ovpn-dco-win data channel offload driver when processing encrypted packets from a connected OpenVPN server with data epoch keys support. A remote user can send crafted encrypted packets to cause a denial of service.

The issue occurs when connecting to an OpenVPN 2.7.0 server or another implementation that supports data epoch keys.


Affected software

OpenVPN Data Channel Offload driver for Windows

How to mitigate CVE-2026-2738

Install security update from vendor's website.

OpenVPN Data Channel Offload driver for Windows - update to 2.8.2

External References

Related Security Bulletins