« Volver al listado

CVE-2026-68341

Estado: RecibidaAlta (8.8)—

In the Linux kernel, the following vulnerability has been resolved:

ovpn: fix use after free in unlock_ovpn()

unlock_ovpn() iterates over the release_list using llist_for_each_entry() and drops the peer reference inside the loop body via ovpn_peer_put().

If this drops the last reference, the peer is eventually freed. However, llist_for_each_entry() reads peer->release_entry.next in the loop advance expression, which runs after the body. By that time the peer may have already been freed, resulting in a use after free when advancing to the next list entry.

Fix this by using llist_for_each_entry_safe(), which caches the next pointer before executing the loop body.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad use-after-free en kernel de Linux requiere acceso local y privilegios (PR:L) para alcanzar unlock_ovpn(). Explotación potencial lleva a escalada de privilegios o DoS. Confianza moderada por ser kernel vulnerability sin CVE activo.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-68341",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "80747caef33d77f5c1b3d24644e6d7dae69066b5",
              "lessThan": "5b96227c0e8b212b74838424c929fc889aedb555",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "80747caef33d77f5c1b3d24644e6d7dae69066b5",
              "lessThan": "4cdb209f12a89c5faf9be0c45edb90ccdf65db0c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "80747caef33d77f5c1b3d24644e6d7dae69066b5",
              "lessThan": "e1ad6fe5db719874efa45b2caf9934552e09fc43",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/ovpn/peer.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.16"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.16",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.42",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/ovpn/peer.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-10T13:20:24.613",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/4cdb209f12a89c5faf9be0c45edb90ccdf65db0c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5b96227c0e8b212b74838424c929fc889aedb555",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e1ad6fe5db719874efa45b2caf9934552e09fc43",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\novpn: fix use after free in unlock_ovpn()\n\nunlock_ovpn() iterates over the release_list using llist_for_each_entry()\nand drops the peer reference inside the loop body via ovpn_peer_put().\n\nIf this drops the last reference, the peer is eventually freed. However,\nllist_for_each_entry() reads peer->release_entry.next in the loop advance\nexpression, which runs after the body. By that time the peer may have\nalready been freed, resulting in a use after free when advancing to the\nnext list entry.\n\nFix this by using llist_for_each_entry_safe(), which caches the next\npointer before executing the loop body."
    }
  ],
  "lastModified": "2026-08-17T06:17:42.307",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}