CVE-2026-68341
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
ovpn: fix use after free in unlock_ovpn()
unlock_ovpn() iterates over the release_list using llist_for_each_entry() and drops the peer reference inside the loop body via ovpn_peer_put().
If this drops the last reference, the peer is eventually freed. However, llist_for_each_entry() reads peer->release_entry.next in the loop advance expression, which runs after the body. By that time the peer may have already been freed, resulting in a use after free when advancing to the next list entry.
Fix this by using llist_for_each_entry_safe(), which caches the next pointer before executing the loop body.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 80747caef33d77f5c1b3d24644e6d7dae69066b5 < 5b96227c0e8b212b74838424c929fc889aedb555 | affected |
| Linux | Linux | 80747caef33d77f5c1b3d24644e6d7dae69066b5 < 4cdb209f12a89c5faf9be0c45edb90ccdf65db0c | affected |
| Linux | Linux | 80747caef33d77f5c1b3d24644e6d7dae69066b5 < e1ad6fe5db719874efa45b2caf9934552e09fc43 | affected |
| Linux | Linux | 6.16 | affected |
| Linux | Linux | 0 < 6.16 | unaffected |
| Linux | Linux | 6.18.42 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.6 <= 7.1.* | unaffected |
| Linux | Linux | 7.2-rc5 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/5b96227c0e8b212b74838424c929fc889aedb555
- https://git.kernel.org/stable/c/4cdb209f12a89c5faf9be0c45edb90ccdf65db0c
- https://git.kernel.org/stable/c/e1ad6fe5db719874efa45b2caf9934552e09fc43
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.