CVE-2026-68122 PUBLISHED

ovpn: fix peer refcount leak in TCP error paths

Assigner: Linux
Reserved: 30.07.2026 Published: 10.08.2026 Updated: 10.08.2026

In the Linux kernel, the following vulnerability has been resolved:

ovpn: fix peer refcount leak in TCP error paths

When either the TCP RX or TX error path calls ovpn_peer_hold() followed by schedule_work(&peer->tcp.defer_del_work), and the work item is already pending from the other path, schedule_work() returns false and the work runs only once. Since ovpn_tcp_peer_del_work() calls ovpn_peer_put() exactly once, the extra reference taken by the losing path is never dropped, leaking the peer object.

The race window:

CPU0 (strparser/RX error): CPU1 (tcp_tx_work/TX error): ovpn_peer_hold() <- refcnt+1 ovpn_peer_hold() <- refcnt+2 schedule_work() <- queued schedule_work() <- NO-OP (work already pending) ovpn_tcp_peer_del_work runs: ovpn_peer_del() ovpn_peer_put() <- refcnt+1 <- peer never freed

Fix by checking the return value of schedule_work() in both paths and calling ovpn_peer_put() to drop the extra reference if the work was already pending. ovpn_peer_hold() is kept unconditional in the TX path as it cannot fail at that point.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from a6a5e87b3ee4cbf9c69a776565378c9b6a91dbfb to b08526bf0bbf84ceebd29033783e8e0c9f451286 (excl.)
  • affected from a6a5e87b3ee4cbf9c69a776565378c9b6a91dbfb to f08f39c1f43f3980d46b06af8ed99ffe84ac294a (excl.)
  • affected from a6a5e87b3ee4cbf9c69a776565378c9b6a91dbfb to 63bbe18fc03062f483c627838a566a707b62da79 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.16 is affected
  • unaffected from 0 to 6.16 (excl.)
  • unaffected from 6.18.42 to 6.18.* (incl.)
  • unaffected from 7.1.6 to 7.1.* (incl.)
  • unaffected from 7.2-rc5 to * (incl.)

References