Junglewise Threat Intelligence

CVE-2026-68122: Linux kernel OVPN refcount leak in TCP error paths

CVE-2026-68122 · Severity: info · Published 2026-08-10

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's OpenVPN (OVPN) driver contains a reference counting bug in its TCP error handling paths. When both RX and TX error paths attempt to schedule peer deletion work simultaneously, one path's reference count increment is never decremented, causing peer objects to leak in memory. This can gradually exhaust kernel memory on systems running OpenVPN over TCP connections.

Technical details

This is a reference counting (refcount) leak vulnerability in the OVPN TCP subsystem (drivers/net/ovpn/tcp.c). The race occurs when both the TCP RX error path (strparser) and TX error path call ovpn_peer_hold() followed by schedule_work(&peer->tcp.defer_del_work) concurrently. When schedule_work() is called from both paths, the second call returns false (work already queued) and doesn't execute. Since ovpn_tcp_peer_del_work() calls ovpn_peer_put() only once, the extra reference from the losing path is never released. The fix checks schedule_work()'s return value and calls ovpn_peer_put() if the work was already pending. No special privileges or network access restrictions apply beyond normal TCP connectivity to trigger the error condition.

Affected products

  • Linux Linux kernel Affected versions include kernel versions containing the OVPN driver with the vulnerable code (fixed in commit 63bbe18fc03062f483c627838a566a707b62da79)

Timeline

  • 2026-08-10: disclosed: CVE-2026-68122 published
  • 2026-05-23: patched: Fix committed by Pavitra Jha (commit 63bbe18fc03062f483c627838a566a707b62da79)
  • 2026-08-03: patched: Backported to stable kernel trees

References

Related threats