{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.18.14-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  ovpn: tcp - don't deref NULL sk_socket member after tcp_close()  When deleting a peer in case of keepalive expiration, the peer is removed from the OpenVPN hashtable and is temporary inserted in a \"release list\" for further processing.  This happens in: ovpn_peer_keepalive_work()   unlock_ovpn(release_list)  This processing includes detaching from the socket being used to talk to this peer, by restoring its original proto and socket ops/callbacks.  In case of TCP it may happen that, while the peer is sitting in the release list, userspace decides to close the socket. This will result in a concurrent execution of:  tcp_close(sk)   __tcp_close(sk)     sock_orphan(sk)       sk_set_socket(sk, NULL)  The last function call will set sk-\u003esk_socket to NULL.  When the releasing routine is resumed, ovpn_tcp_socket_detach() will attempt to dereference sk-\u003esk_socket to restore its original ops member. This operation will crash due to sk-\u003esk_socket being NULL.  Fix this race condition by testing-and-accessing sk-\u003esk_socket atomically under sk-\u003esk_callback_lock.",
  "id": "DEBIAN-CVE-2026-45918",
  "modified": "2026-09-14T16:47:32.342115509Z",
  "published": "2026-05-27T14:17:06.690Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-45918"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-45918"
  ]
}