CVE-2026-80735 PUBLISHED

ovpn: ensure socket is owned by ovpn before deref sk_user_data

Assigner: Linux
Reserved: 26.08.2026 Published: 03.09.2026 Updated: 03.09.2026

In the Linux kernel, the following vulnerability has been resolved:

ovpn: ensure socket is owned by ovpn before deref sk_user_data

Some subsystems, like BPF SOCKMAP, set sk_user_data without actually setting the encap_type.

For this reason, we must make sure that the type is the one ovpn expects before dereferencing sk_user_data.

Failing to do so may lead to out-of-bounds reads.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from f6226ae7a0cd47aaa9175aca6a1e19600f884cbf to 61fb3cca40ff938671474f4a16adb908c19032d7 (excl.)
  • affected from f6226ae7a0cd47aaa9175aca6a1e19600f884cbf to 43a31142e1d22b3cf5490bd94a94db7196901734 (excl.)
  • affected from f6226ae7a0cd47aaa9175aca6a1e19600f884cbf to 59aed1eb60d70678a53acccb0cb337a26ce6680e (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.16 is affected
  • unaffected from 0 to 6.16 (excl.)
  • unaffected from 6.18.45 to 6.18.* (incl.)
  • unaffected from 7.1.9 to 7.1.* (incl.)
  • unaffected from 7.2 to * (incl.)

References