CVE-2026-80735
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
ovpn: ensure socket is owned by ovpn before deref sk_user_data
Some subsystems, like BPF SOCKMAP, set sk_user_data without actually setting the encap_type.
For this reason, we must make sure that the type is the one ovpn expects before dereferencing sk_user_data.
Failing to do so may lead to out-of-bounds reads.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | f6226ae7a0cd47aaa9175aca6a1e19600f884cbf < 61fb3cca40ff938671474f4a16adb908c19032d7 | affected |
| Linux | Linux | f6226ae7a0cd47aaa9175aca6a1e19600f884cbf < 43a31142e1d22b3cf5490bd94a94db7196901734 | affected |
| Linux | Linux | f6226ae7a0cd47aaa9175aca6a1e19600f884cbf < 59aed1eb60d70678a53acccb0cb337a26ce6680e | affected |
| Linux | Linux | 6.16 | affected |
| Linux | Linux | 0 < 6.16 | unaffected |
| Linux | Linux | 6.18.45 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.9 <= 7.1.* | unaffected |
| Linux | Linux | 7.2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/61fb3cca40ff938671474f4a16adb908c19032d7
- https://git.kernel.org/stable/c/43a31142e1d22b3cf5490bd94a94db7196901734
- https://git.kernel.org/stable/c/59aed1eb60d70678a53acccb0cb337a26ce6680e
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.