๐Ÿ” CVE Alert

CVE-2026-80520

UNKNOWN 0.0

ovpn: fix NULL dereference when killing missing key

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ovpn: fix NULL dereference when killing missing key ovpn_crypto_kill_key assumes both crypto slots are populated and dereferences each slot before checking it. That is not guaranteed: a peer can have only one installed key, and the kill path may be asked to remove a key that is not present. Read each slot once while holding the crypto state lock, check for NULL before looking at key_id, and only replace the slot that actually matches.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 26, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
89d3c0e4612afa1c6429ed68d298e35592fbe208 < a47a080d06ee9d94dc6a2da0fc2b9beeeedb92b3 89d3c0e4612afa1c6429ed68d298e35592fbe208 < acf32a5dff082044cf0fd9492f3c10b7357c15ee 89d3c0e4612afa1c6429ed68d298e35592fbe208 < 41d44ac7a61e2f74453af40d4fe1b82af9ea0ada
Linux / Linux
6.16

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/a47a080d06ee9d94dc6a2da0fc2b9beeeedb92b3 git.kernel.org: https://git.kernel.org/stable/c/acf32a5dff082044cf0fd9492f3c10b7357c15ee git.kernel.org: https://git.kernel.org/stable/c/41d44ac7a61e2f74453af40d4fe1b82af9ea0ada