PT-2026-84933 · Linux · Linux

CVE-2026-80735

·

Publicado

2026-09-03

·

Atualizado

2026-09-03

CVSS v3.1

7.3

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
In the Linux kernel, the following vulnerability has been resolved:
ovpn: ensure socket is owned by ovpn before deref sk user data
Some subsystems, like BPF SOCKMAP, set sk user data without actually setting the encap type.
For this reason, we must make sure that the type is the one ovpn expects before dereferencing sk user data.
Failing to do so may lead to out-of-bounds reads.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-80735

Produtos afetados

Linux