Executive brief
A race condition was identified in the Linux kernel's OpenVPN (ovpn) module when handling TCP connections. This flaw could allow a local attacker to cause a system crash or instability by closing a network connection at the exact moment a peer is being removed. While primarily affecting system availability, it represents a reliability risk for servers utilizing OpenVPN with TCP transport.
Technical details
A race condition exists in `ovpn_tcp_close()` within the Linux kernel's OpenVPN implementation. The function dereferences `sock->peer` outside of an RCU read-side critical section without holding the socket lock. This creates a window where `ovpn_socket_release()` can concurrently execute its cleanup sequence (kref_put, detach, synchronize_rcu, and kfree), leading to a use-after-free or NULL pointer dereference when `ovpn_tcp_close()` eventually attempts to use the pointer. The vulnerability is triggered when a peer removal event (such as keepalive expiration) coincides with userspace closing the TCP file descriptor. The fix involves caching the peer pointer locally within the RCU-protected section to ensure its validity during subsequent operations.
Affected products
- Linux Linux Kernel 11851cbd60ea to e5460eb7238c
Timeline
- 2026-05-13: other: Patch authored
- 2026-07-19: disclosed: CVE published