« Volver al listado

CVE-2026-80753

Estado: RecibidaAlta (8.4)—

In the Linux kernel, the following vulnerability has been resolved:

ovpn: run deferred work on a module-owned workqueue

ovpn queues several work items whose callbacks execute module text. These works currently run on the global system workqueues, so module exit has no driver-owned drain point that guarantees the callbacks have fully returned before the module text can be freed.

Object references protect the objects used by the callbacks, but they do not prove that a workqueue function has returned. In particular, a worker can drop the final reference that unblocks device teardown while it is still executing ovpn code.

Leer descripción completaMostrar menos

Add a module-owned workqueue and queue all ovpn work items on it. During module exit, unregister rtnl and netlink first, flush the workqueue so ordinary ovpn workers finish, run the final RCU barrier, and destroy the workqueue last. This keeps the workqueue available for cleanup work queued from RCU callbacks, while ensuring no ovpn work item can outlive the module text.

The per-device delayed keepalive work remains explicitly disabled during netdev teardown (disable_delayed_work_sync in ndo_uninit), since flush_workqueue does not flush delayed work that is still only pending on its timer.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:L sin UI ni PR indica escalada local. El kernel permite ejecutar código con privilegios elevados al explotar la race condition en workqueue. Potencial DoS por corrupción de memoria.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80753",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.4,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.5
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "11851cbd60ea1e5abbd97619d69845ead99303d6",
              "lessThan": "b5fe67111e63a8a81ec31056c4475509076fd266",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "11851cbd60ea1e5abbd97619d69845ead99303d6",
              "lessThan": "bbe81f40582d451ac849b20707784220f33a23bd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "11851cbd60ea1e5abbd97619d69845ead99303d6",
              "lessThan": "e9714db8041763f59dde152c812b96b3de05c6d9",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/ovpn/main.c",
            "drivers/net/ovpn/ovpnpriv.h",
            "drivers/net/ovpn/peer.c",
            "drivers/net/ovpn/tcp.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.16"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.16",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.50",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.10",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/ovpn/main.c",
            "drivers/net/ovpn/ovpnpriv.h",
            "drivers/net/ovpn/peer.c",
            "drivers/net/ovpn/tcp.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-03T13:06:15.010",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/b5fe67111e63a8a81ec31056c4475509076fd266",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bbe81f40582d451ac849b20707784220f33a23bd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e9714db8041763f59dde152c812b96b3de05c6d9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\novpn: run deferred work on a module-owned workqueue\n\novpn queues several work items whose callbacks execute module text.\nThese works currently run on the global system workqueues, so module\nexit has no driver-owned drain point that guarantees the callbacks have\nfully returned before the module text can be freed.\n\nObject references protect the objects used by the callbacks, but they do\nnot prove that a workqueue function has returned. In particular, a\nworker can drop the final reference that unblocks device teardown while\nit is still executing ovpn code.\n\nAdd a module-owned workqueue and queue all ovpn work items on it. During\nmodule exit, unregister rtnl and netlink first, flush the workqueue so\nordinary ovpn workers finish, run the final RCU barrier, and destroy the\nworkqueue last. This keeps the workqueue available for cleanup work\nqueued from RCU callbacks, while ensuring no ovpn work item can outlive\nthe module text.\n\nThe per-device delayed keepalive work remains explicitly disabled during\nnetdev teardown (disable_delayed_work_sync in ndo_uninit), since\nflush_workqueue does not flush delayed work that is still only pending\non its timer."
    }
  ],
  "lastModified": "2026-09-07T16:17:30.097",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}