CVE-2026-68122
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
ovpn: fix peer refcount leak in TCP error paths
When either the TCP RX or TX error path calls ovpn_peer_hold() followed by schedule_work(&peer->tcp.defer_del_work), and the work item is already pending from the other path, schedule_work() returns false and the work runs only once. Since ovpn_tcp_peer_del_work() calls ovpn_peer_put() exactly once, the extra reference taken by the losing path is never dropped, leaking the peer object.
The race window:
CPU0 (strparser/RX error): CPU1 (tcp_tx_work/TX error): ovpn_peer_hold() <- refcnt+1 ovpn_peer_hold() <- refcnt+2 schedule_work() <- queued schedule_work() <- NO-OP (work already pending) ovpn_tcp_peer_del_work runs: ovpn_peer_del() ovpn_peer_put() <- refcnt+1 <- peer never freed
Fix by checking the return value of schedule_work() in both paths and calling ovpn_peer_put() to drop the extra reference if the work was already pending. ovpn_peer_hold() is kept unconditional in the TX path as it cannot fail at that point.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | a6a5e87b3ee4cbf9c69a776565378c9b6a91dbfb < b08526bf0bbf84ceebd29033783e8e0c9f451286 | affected |
| Linux | Linux | a6a5e87b3ee4cbf9c69a776565378c9b6a91dbfb < f08f39c1f43f3980d46b06af8ed99ffe84ac294a | affected |
| Linux | Linux | a6a5e87b3ee4cbf9c69a776565378c9b6a91dbfb < 63bbe18fc03062f483c627838a566a707b62da79 | affected |
| Linux | Linux | 6.16 | affected |
| Linux | Linux | 0 < 6.16 | unaffected |
| Linux | Linux | 6.18.42 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.6 <= 7.1.* | unaffected |
| Linux | Linux | 7.2-rc5 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/b08526bf0bbf84ceebd29033783e8e0c9f451286
- https://git.kernel.org/stable/c/f08f39c1f43f3980d46b06af8ed99ffe84ac294a
- https://git.kernel.org/stable/c/63bbe18fc03062f483c627838a566a707b62da79
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.