๐Ÿ” CVE Alert

CVE-2026-68341

UNKNOWN 0.0

ovpn: fix use after free in unlock_ovpn()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ovpn: fix use after free in unlock_ovpn() unlock_ovpn() iterates over the release_list using llist_for_each_entry() and drops the peer reference inside the loop body via ovpn_peer_put(). If this drops the last reference, the peer is eventually freed. However, llist_for_each_entry() reads peer->release_entry.next in the loop advance expression, which runs after the body. By that time the peer may have already been freed, resulting in a use after free when advancing to the next list entry. Fix this by using llist_for_each_entry_safe(), which caches the next pointer before executing the loop body.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
80747caef33d77f5c1b3d24644e6d7dae69066b5 < 5b96227c0e8b212b74838424c929fc889aedb555 80747caef33d77f5c1b3d24644e6d7dae69066b5 < 4cdb209f12a89c5faf9be0c45edb90ccdf65db0c 80747caef33d77f5c1b3d24644e6d7dae69066b5 < e1ad6fe5db719874efa45b2caf9934552e09fc43
Linux / Linux
6.16

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/5b96227c0e8b212b74838424c929fc889aedb555 git.kernel.org: https://git.kernel.org/stable/c/4cdb209f12a89c5faf9be0c45edb90ccdf65db0c git.kernel.org: https://git.kernel.org/stable/c/e1ad6fe5db719874efa45b2caf9934552e09fc43