Buffer overflow in OpenVPN ovpn-dco-win version 1.3.0 and earlier and version 2.5.8 and earlier allows a local user process to send a too large control message buffer to the kernel driver resulting in a system crash
History

Mon, 23 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 20 Jun 2025 07:00:00 +0000


Fri, 20 Jun 2025 06:45:00 +0000

Type Values Removed Values Added
Description Buffer overflow in OpenVPN ovpn-dco-win version 1.3.0 and earlier and version 2.5.8 and earlier allows a local user process to send a too large control message buffer to the kernel driver resulting in a system crash
Weaknesses CWE-122
CWE-787
References

cve-icon MITRE

Status: PUBLISHED

Assigner: OpenVPN

Published: 2025-06-20T06:29:01.936Z

Updated: 2025-06-23T15:48:43.804Z

Reserved: 2025-06-11T17:29:58.718Z

Link: CVE-2025-50054

cve-icon Vulnrichment

Updated: 2025-06-23T15:48:25.555Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-20T07:15:26.367

Modified: 2025-06-23T20:16:40.143

Link: CVE-2025-50054

cve-icon Redhat

No data.