CVE-2026-45929

Source
https://cve.org/CVERecord?id=CVE-2026-45929
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45929.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-45929
Downstream
Published
2026-05-27T12:17:47Z
Modified
2026-08-12T03:51:38Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
ovpn: fix possible use-after-free in ovpn_net_xmit
Details

In the Linux kernel, the following vulnerability has been resolved:

ovpn: fix possible use-after-free in ovpn_net_xmit

When building the skb_list in ovpn_net_xmit, skb_share_check will free the original skb if it is shared. The current implementation continues to use the stale skb pointer for subsequent operations:

  • peer lookup,
  • skb_dst_drop (even though all segments produced by skb_gso_segment will have a dst attached),
  • ovpn_peer_stats_increment_tx.

Fix this by moving the peer lookup and skb_dst_drop before segmentation so that the original skb is still valid when used. Return early if all segments fail skb_share_check and the list ends up empty. Also switch ovpn_peer_stats_increment_tx to use skb_list.next; the next patch fixes the stats logic.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45929.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
08857b5ec5d91d83e69e40a36554a8c7557b7301
Fixed
3e4fbcb4e078915367ba5576cd70d76dbc970f95
Fixed
442915c96a9bff1c7080e2aedabb1c03faa28d81
Fixed
a5ec7baa44ea3a1d6aa0ca31c0ad82edf9affe41

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45929.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.16.0
Fixed
6.18.14
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45929.json"