{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "11851cbd60ea1e5abbd97619d69845ead99303d6"
            },
            {
              "fixed": "8298834912d76dbc82c12b6b4ab7590ed2bb8ae5"
            },
            {
              "fixed": "0c3ef71879c0264de6c42463031d9e057da87840"
            },
            {
              "fixed": "1fef6614673ff0846d30acdeeaf3cf98bb5f6116"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "6.16.0"
            },
            {
              "fixed": "6.18.34"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.0.11"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64044.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\novpn: respect peer refcount in CMD_NEW_PEER error path\n\novpn_nl_peer_new_doit()'s error path calls ovpn_peer_release() directly\nrather than ovpn_peer_put(), bypassing the kref. The accompanying\ncomment (\"peer was not yet hashed, thus it is not used in any context\")\nholds for UDP but not for TCP.\n\nFor UDP, the ovpn_socket union uses the .ovpn arm and never points back\nat a peer; UDP encap_recv looks up peers via the not-yet-populated\nhashtables, so the new peer is unreachable until ovpn_peer_add()\npublishes it.\n\nFor TCP, ovpn_socket_new() sets ovpn_sock-\u003epeer and\novpn_tcp_socket_attach() publishes ovpn_sock via rcu_assign_sk_user_data().\nFrom that moment until ovpn_socket_release() detaches in the error path,\nthe TCP fd is fully wired: userspace recvmsg / sendmsg / close / poll\non the fd, as well as the strparser-driven ovpn_tcp_rcv() path, can\nreach the peer through sk_user_data -\u003e ovpn_sock-\u003epeer and bump its\nrefcount via ovpn_peer_hold().\n\novpn_tcp_socket_wait_finish() (called inside ovpn_socket_release())\ndrains strparser and the tx work, but does not synchronize with\nuserspace syscall callers that already hold a peer reference. If\novpn_nl_peer_modify() or ovpn_peer_add() returns an error while such\na caller is in flight - notably an ovpn_tcp_recvmsg() blocked in\n__skb_recv_datagram() on peer-\u003etcp.user_queue - the direct\novpn_peer_release() destroys the peer while the caller still holds\nthe reference, and the eventual ovpn_peer_put() from that caller\noperates on freed memory.\n\nReplace the direct destructor call with ovpn_peer_put() so the kref\ncorrectly defers destruction until the last reference is dropped.\nIn the common case where no concurrent user is present, behaviour is\nunchanged: the kref hits zero immediately and ovpn_peer_release_kref()\nruns the same destructor.\n\nWith this conversion ovpn_peer_release() has no callers outside peer.c\n- ovpn_peer_release_kref() in the same translation unit is the only\nremaining user - so make it static and drop its declaration from\npeer.h.",
  "id": "CVE-2026-64044",
  "modified": "2026-07-22T05:29:47.634800624Z",
  "published": "2026-07-19T15:39:29.869Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/0c3ef71879c0264de6c42463031d9e057da87840"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/1fef6614673ff0846d30acdeeaf3cf98bb5f6116"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/8298834912d76dbc82c12b6b4ab7590ed2bb8ae5"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64044.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64044"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.8.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "ovpn: respect peer refcount in CMD_NEW_PEER error path"
}