Linux Kernel Vulnerability in OpenVPN Socket Ownership
CVE-2026-80735
What is CVE-2026-80735?
A vulnerability has been identified in the Linux kernel affecting OpenVPN, where the ownership of sockets was not properly enforced before dereferencing the sk_user_data. Subsystems like BPF SOCKMAP may set sk_user_data without ensuring it complies with the expected encapsulation type. This oversight can result in potential out-of-bounds reads, posing a significant security risk if exploited. It is crucial for users and administrators to apply the latest kernel updates to mitigate this issue.
Affected Version(s)
Linux f6226ae7a0cd47aaa9175aca6a1e19600f884cbf < 61fb3cca40ff938671474f4a16adb908c19032d7
Linux f6226ae7a0cd47aaa9175aca6a1e19600f884cbf < 43a31142e1d22b3cf5490bd94a94db7196901734
Linux f6226ae7a0cd47aaa9175aca6a1e19600f884cbf < 59aed1eb60d70678a53acccb0cb337a26ce6680e