NULL pointer dereference in Linux kernel - CVE-2026-80520
Published: August 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in ovpn_crypto_kill_key in the ovpn crypto component when handling a request to remove a missing key. A remote attacker can trigger key removal for a key that is not present to cause a denial of service.
A peer may have only one installed key, which can leave one crypto slot empty.