In the Linux kernel, the following vulnerability has been resolved:
ovpn: respect peer refcount in CMD_NEW_PEER error path
ovpn_nl_peer_new_doit()'s error path calls ovpn_peer_release() directly rather than ovpn_peer_put(), bypassing the kref. The accompanying comment ("peer was not yet hashed, thus it is not used in any context") holds for UDP but not for TCP.
For UDP, the ovpn_socket union uses the .ovpn arm and never points back at a peer; UDP encap_recv looks up peers via the not-yet-populated hashtables, so the new peer is unreachable until ovpn_peer_add() publishes it.
For TCP, ovpn_socket_new() sets ovpn_sock->peer and ovpn_tcp_socket_attach() publishes ovpn_sock via rcu_assign_sk_user_data(). From that moment until ovpn_socket_release() detaches in the error path, the TCP fd is fully wired: userspace recvmsg / sendmsg / close / poll on the fd, as well as the strparser-driven ovpn_tcp_rcv() path, can reach the peer through sk_user_data -> ovpn_sock->peer and bump its refcount via ovpn_peer_hold().
ovpn_tcp_socket_wait_finish() (called inside ovpn_socket_release()) drains strparser and the tx work, but does not synchronize with userspace syscall callers that already hold a peer reference. If ovpn_nl_peer_modify() or ovpn_peer_add() returns an error while such a caller is in flight - notably an ovpn_tcp_recvmsg() blocked in __skb_recv_datagram() on peer->tcp.user_queue - the direct ovpn_peer_release() destroys the peer while the caller still holds the reference, and the eventual ovpn_peer_put() from that caller operates on freed memory.
Replace the direct destructor call with ovpn_peer_put() so the kref correctly defers destruction until the last reference is dropped. In the common case where no concurrent user is present, behaviour is unchanged: the kref hits zero immediately and ovpn_peer_release_kref() runs the same destructor.
With this conversion ovpn_peer_release() has no callers outside peer.c - ovpn_peer_release_kref() in the same translation unit is the only remaining user - so make it static and drop its declaration from peer.h.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade kernel6.18-debuginfo-common-x86_64Upgrade kernel6.18-headersUpgrade kernel6.18-tools-develUpgrade kernel6.18Upgrade kernel6.18-debuginfoUpgrade bpftool6.18-debuginfoUpgrade kernel6.18-develUpgrade kernel6.18-toolsUpgrade microvm-kernel6.18Upgrade kernel6.18-modules-extraUpgrade perf6.18-debuginfoUpgrade kernel6.18-modules-extra-commonUpgrade perf6.18Upgrade python3-perf6.18-debuginfoUpgrade kernel6.18-tools-debuginfoUpgrade kernel6.18-debuginfo-common-aarch64Upgrade bpftool6.18Upgrade python3-perf6.18Upgrade kernel-livepatch-6.18.35-68.127 | Aug 10, 2026 | Jul 19, 2026 |
| Ubuntu | — | Upgrade linux-image-7.0.0-1015-raspi-realtimeUpgrade linux-image-7.0.0-2016-nvidia-bos-64kUpgrade linux-image-oracleUpgrade linux-image-7.0.0-1016-nvidiaUpgrade linux-image-awsUpgrade linux-image-gcp-64k-7.0Upgrade linux-image-gcp-7.0Upgrade linux-image-raspi-7.0Upgrade linux-image-7.0.0-1009-azure-fdeUpgrade linux-image-aws-64kUpgrade linux-image-nvidia-64kUpgrade linux-image-oracle-64k-7.0Upgrade linux-image-aws-7.0Upgrade linux-image-oracle-64kUpgrade linux-image-7.0.0-1011-oracle-64kUpgrade linux-image-7.0.0-1015-raspiUpgrade linux-image-7.0.0-1008-oracle-64kUpgrade linux-image-raspi-realtime-7.0Upgrade linux-image-7.0.0-1014-azureUpgrade linux-image-aws-64k-7.0Upgrade linux-image-7.0.0-1008-oracleUpgrade linux-image-azure-7.0Upgrade linux-image-nvidia-bosUpgrade linux-image-azure-fdeUpgrade linux-image-nvidia-bos-7.0Upgrade linux-image-nvidia-hwe-26.04Upgrade linux-image-nvidia-64k-hwe-26.04Upgrade linux-image-nvidiaUpgrade linux-image-7.0.0-1010-ibmUpgrade linux-image-7.0.0-1016-nvidia-64kUpgrade linux-image-7.0.0-1011-gcp-64kUpgrade linux-image-nvidia-64k-7.0Upgrade linux-image-7.0.0-1009-aws-64kUpgrade linux-image-7.0.0-1009-awsUpgrade linux-image-7.0.0-1011-oracleUpgrade linux-image-nvidia-bos-64k-7.0Upgrade linux-image-ibmUpgrade linux-image-gcpUpgrade linux-image-nvidia-bos-64kUpgrade linux-image-azure-fde-7.0Upgrade linux-image-7.0.0-1011-gcpUpgrade linux-image-7.0.0-1010-azureUpgrade linux-image-raspi-realtimeUpgrade linux-image-ibm-7.0Upgrade linux-image-gcp-64kUpgrade linux-image-7.0.0-2016-nvidia-bosUpgrade linux-image-oracle-7.0Upgrade linux-image-raspiUpgrade linux-image-nvidia-7.0Upgrade linux-image-azure | Jul 21, 2026 | Jul 20, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub