CVE-2026-68341

Published: Ago 10, 2026 Last Modified: Ago 10, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

In the Linux kernel, the following vulnerability has been resolved:

ovpn: fix use after free in unlock_ovpn()

unlock_ovpn() iterates over the release_list using llist_for_each_entry()
and drops the peer reference inside the loop body via ovpn_peer_put().

If this drops the last reference, the peer is eventually freed. However,
llist_for_each_entry() reads peer->release_entry.next in the loop advance
expression, which runs after the body. By that time the peer may have
already been freed, resulting in a use after free when advancing to the
next list entry.

Fix this by using llist_for_each_entry_safe(), which caches the next
pointer before executing the loop body.

https://git.kernel.org/stable/c/4cdb209f12a89c5faf9be0c45edb90ccdf65db0c
https://git.kernel.org/stable/c/5b96227c0e8b212b74838424c929fc889aedb555
https://git.kernel.org/stable/c/e1ad6fe5db719874efa45b2caf9934552e09fc43