Use-after-free in Linux kernel - CVE-2026-80519
Published: August 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a use-after-free in the ovpn crypto completion callback handling in drivers/net/ovpn/io.c when processing crafted network packets. A remote attacker can send crafted packets that trigger asynchronous callback cleanup after peer release to execute arbitrary code.
The issue is caused by releasing the peer reference before key-slot cleanup and skb freeing are completed in the callback path.