CVE-2026-68122

Summary

In the Linux kernel, the following vulnerability has been resolved:

ovpn: fix peer refcount leak in TCP error paths

When either the TCP RX or TX error path calls ovpn_peer_hold() followed by schedule_work(&peer->tcp.defer_del_work), and the work item is already pending from the other path, schedule_work() returns false and the work runs only once. Since ovpn_tcp_peer_del_work() calls ovpn_peer_put() exactly once, the extra reference taken by the losing path is never dropped, leaking the peer object.

The race window:

CPU0 (strparser/RX error): CPU1 (tcp_tx_work/TX error): ovpn_peer_hold() <- refcnt+1 ovpn_peer_hold() <- refcnt+2 schedule_work() <- queued schedule_work() <- NO-OP (work already pending) ovpn_tcp_peer_del_work runs: ovpn_peer_del() ovpn_peer_put() <- refcnt+1 <- peer never freed

Fix by checking the return value of schedule_work() in both paths and calling ovpn_peer_put() to drop the extra reference if the work was already pending. ovpn_peer_hold() is kept unconditional in the TX path as it cannot fail at that point.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxa6a5e87b3ee4cbf9c69a776565378c9b6a91dbfb < b08526bf0bbf84ceebd29033783e8e0c9f451286affected
LinuxLinuxa6a5e87b3ee4cbf9c69a776565378c9b6a91dbfb < f08f39c1f43f3980d46b06af8ed99ffe84ac294aaffected
LinuxLinuxa6a5e87b3ee4cbf9c69a776565378c9b6a91dbfb < 63bbe18fc03062f483c627838a566a707b62da79affected
LinuxLinux6.16affected
LinuxLinux0 < 6.16unaffected
LinuxLinux6.18.42 <= 6.18.*unaffected
LinuxLinux7.1.6 <= 7.1.*unaffected
LinuxLinux7.2-rc5 <= *unaffected

Weaknesses

References