Use-after-free in Linux kernel - CVE-2026-80753

 

Use-after-free in Linux kernel - CVE-2026-80753

Published: September 4, 2026


Vulnerability identifier: #VU146911
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80753
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local privileged user to cause a use-after-free of module text.

The vulnerability exists due to improper workqueue lifecycle management in ovpn deferred work handling when unloading the ovpn module while its work items execute on global system workqueues. A local privileged user can unload the ovpn module while ovpn work items remain queued to cause a use-after-free of module text.


Affected software

Linux kernel

How to mitigate CVE-2026-80753

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins