CVE-2026-68341

In the Linux kernel, the following vulnerability has been resolved: ovpn: fix use after free in unlock_ovpn() unlock_ovpn() iterates over the release_list using llist_for_each_entry() and drops the peer reference inside the loop body via ovpn_peer_put(). If this drops the last reference, the peer is eventually freed. However, llist_for_each_entry() reads peer->release_entry.next in the loop advance expression, which runs after the body. By that time the peer may have already been freed, resulting in a use after free when advancing to the next list entry. Fix this by using llist_for_each_entry_safe(), which caches the next pointer before executing the loop body.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-10 13:20

Updated : 2026-08-17 06:17


NVD link : CVE-2026-68341

Mitre link : CVE-2026-68341

CVE.ORG link : CVE-2026-68341


JSON object : View

Products Affected

No product.

CWE

No CWE.