CVE-2026-64044
Received Received - Intake

Reference Leak in OpenVPN Kernel Module

Vulnerability report for CVE-2026-64044, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-19

Last updated on: 2026-07-19

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: ovpn: respect peer refcount in CMD_NEW_PEER error path ovpn_nl_peer_new_doit()'s error path calls ovpn_peer_release() directly rather than ovpn_peer_put(), bypassing the kref. The accompanying comment ("peer was not yet hashed, thus it is not used in any context") holds for UDP but not for TCP. For UDP, the ovpn_socket union uses the .ovpn arm and never points back at a peer; UDP encap_recv looks up peers via the not-yet-populated hashtables, so the new peer is unreachable until ovpn_peer_add() publishes it. For TCP, ovpn_socket_new() sets ovpn_sock->peer and ovpn_tcp_socket_attach() publishes ovpn_sock via rcu_assign_sk_user_data(). From that moment until ovpn_socket_release() detaches in the error path, the TCP fd is fully wired: userspace recvmsg / sendmsg / close / poll on the fd, as well as the strparser-driven ovpn_tcp_rcv() path, can reach the peer through sk_user_data -> ovpn_sock->peer and bump its refcount via ovpn_peer_hold(). ovpn_tcp_socket_wait_finish() (called inside ovpn_socket_release()) drains strparser and the tx work, but does not synchronize with userspace syscall callers that already hold a peer reference. If ovpn_nl_peer_modify() or ovpn_peer_add() returns an error while such a caller is in flight - notably an ovpn_tcp_recvmsg() blocked in __skb_recv_datagram() on peer->tcp.user_queue - the direct ovpn_peer_release() destroys the peer while the caller still holds the reference, and the eventual ovpn_peer_put() from that caller operates on freed memory. Replace the direct destructor call with ovpn_peer_put() so the kref correctly defers destruction until the last reference is dropped. In the common case where no concurrent user is present, behaviour is unchanged: the kref hits zero immediately and ovpn_peer_release_kref() runs the same destructor. With this conversion ovpn_peer_release() has no callers outside peer.c - ovpn_peer_release_kref() in the same translation unit is the only remaining user - so make it static and drop its declaration from peer.h.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-19
Last Modified
2026-07-19
Generated
2026-07-20
AI Q&A
2026-07-19
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openvpn openvpn *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Linux kernel vulnerability in the OpenVPN (ovpn) driver. The issue occurs in the error handling path of the CMD_NEW_PEER command. When an error happens during peer creation, the code incorrectly releases the peer reference directly instead of using the proper reference counting mechanism (kref). This bypasses the reference tracking, leading to potential use-after-free scenarios where the peer object is freed while still in use by other parts of the system.

Detection Guidance

This vulnerability is specific to the Linux kernel's OpenVPN implementation and requires kernel-level inspection. Detection involves checking kernel logs for errors related to ovpn_peer_release or ovpn_peer_put, or verifying if your kernel version includes the patched code. Commands like dmesg, journalctl -k, or checking kernel version with uname -a may help identify affected systems.

Impact Analysis

This vulnerability could allow an attacker to cause a denial-of-service (system crash) or potentially execute arbitrary code with kernel privileges. It specifically affects systems using OpenVPN over TCP, as the issue is more pronounced in TCP mode due to how socket references are managed. Users of affected Linux kernels could experience system instability or security breaches.

Compliance Impact

This vulnerability does not directly affect compliance with standards like GDPR or HIPAA as it pertains to a specific Linux kernel component (ovpn) and involves a memory management issue in peer reference counting. Compliance implications would depend on how the affected system is used, not the vulnerability itself.

Mitigation Strategies

Apply the latest kernel update that includes the fix for CVE-2026-64044. If immediate patching is not possible, consider disabling OpenVPN TCP mode as a temporary workaround until the kernel is updated.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-64044. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart