Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ovpn: fix peer refcount leak in TCP error paths When either the TCP RX or TX error path calls ovpn_peer_hold() followed by schedule_work(&peer->tcp.defer_del_work), and the work item is already pending from the other path, schedule_work() returns false and the work runs only once. Since ovpn_tcp_peer_del_work() calls ovpn_peer_put() exactly once, the extra reference taken by the losing path is never dropped, leaking the peer object. The race window: CPU0 (strparser/RX error): CPU1 (tcp_tx_work/TX error): ovpn_peer_hold() <- refcnt+1 ovpn_peer_hold() <- refcnt+2 schedule_work() <- queued schedule_work() <- NO-OP (work already pending) ovpn_tcp_peer_del_work runs: ovpn_peer_del() ovpn_peer_put() <- refcnt+1 <- peer never freed Fix by checking the return value of schedule_work() in both paths and calling ovpn_peer_put() to drop the extra reference if the work was already pending. ovpn_peer_hold() is kept unconditional in the TX path as it cannot fail at that point.
References
- https://git.kernel.org/stable/c/63bbe18fc03062f483c627838a566a707b62da79
- https://git.kernel.org/stable/c/b08526bf0bbf84ceebd29033783e8e0c9f451286
- https://git.kernel.org/stable/c/f08f39c1f43f3980d46b06af8ed99ffe84ac294a
FAQ
What is CVE-2026-68122?
CVE-2026-68122 is a documented vulnerability. In the Linux kernel, the following vulnerability has been resolved: ovpn: fix peer refcount leak in TCP error paths When either the TCP RX or TX error path calls ovpn_peer_hold() followed by schedul...
How severe is CVE-2026-68122?
CVSS scoring is not yet available for CVE-2026-68122. Check NVD for updates.
Is there a patch for CVE-2026-68122?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.