Executive brief
A vulnerability was identified in the Linux kernel's OpenVPN (ovpn) module, which handles high-speed VPN networking. Under certain conditions when processing network traffic, the system could attempt to use memory that has already been freed. This could lead to system instability, crashes, or potentially allow an attacker to disrupt VPN services.
Technical details
A use-after-free (UAF) vulnerability exists in the ovpn_net_xmit function within the Linux kernel's ovpn driver. When building an skb_list, the skb_share_check function may free the original socket buffer (skb) if it is shared. The code incorrectly continued to use the stale skb pointer for peer lookups, destination dropping, and statistics increments. An attacker could potentially trigger this condition to cause a kernel oops or memory corruption. The fix involves reordering operations to ensure peer lookup and destination dropping occur before the skb is potentially freed during segmentation.
Affected products
- Linux Linux Kernel ovpn module introduced in 6.13-rc1
Timeline
- 2026-01-30: other: Patch authored
- 2026-05-27: disclosed: CVE published
- 2026-05-27: patched: Fixes merged into stable branches