Out-of-bounds read in Linux kernel - CVE-2026-80735
Published: September 4, 2026
Vulnerability details
The vulnerability allows a local user to read out-of-bounds memory.
The vulnerability exists due to an out-of-bounds read in the ovpn socket handling code when processing a socket whose sk_user_data is set without the expected encapsulation type. A local user can cause ovpn to dereference the socket's sk_user_data to read out-of-bounds memory.