7.5

CVE-2026-80520

ovpn: fix NULL dereference when killing missing key

In the Linux kernel, the following vulnerability has been resolved:

ovpn: fix NULL dereference when killing missing key

ovpn_crypto_kill_key assumes both crypto slots are populated and
dereferences each slot before checking it. That is not guaranteed: a
peer can have only one installed key, and the kill path may be asked to
remove a key that is not present.

Read each slot once while holding the crypto state lock, check for NULL
before looking at key_id, and only replace the slot that actually
matches.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 89d3c0e4612afa1c6429ed68d298e35592fbe208
Version < a47a080d06ee9d94dc6a2da0fc2b9beeeedb92b3
Status affected
Version 89d3c0e4612afa1c6429ed68d298e35592fbe208
Version < acf32a5dff082044cf0fd9492f3c10b7357c15ee
Status affected
Version 89d3c0e4612afa1c6429ed68d298e35592fbe208
Version < 41d44ac7a61e2f74453af40d4fe1b82af9ea0ada
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.16
Status affected
Version 0
Version < 6.16
Status unaffected
Version <= 6.18.*
Version 6.18.46
Status unaffected
Version <= 7.1.*
Version 7.1.10
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.43% 0.359
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/a47a080d06ee9d94dc6a2da0fc2b9beeeedb92b3
https://git.kernel.org/stable/c/acf32a5dff082044cf0fd9492f3c10b7357c15ee
https://git.kernel.org/stable/c/41d44ac7a61e2f74453af40d4fe1b82af9ea0ada