]> git.ipfire.org Git - thirdparty/kernel/linux.git/commit
ovpn: fix NULL dereference when killing missing key
authorRalf Lici <ralf@mandelbit.com>
Wed, 29 Jul 2026 10:21:41 +0000 (12:21 +0200)
committerAntonio Quartulli <antonio@openvpn.net>
Fri, 7 Aug 2026 00:12:13 +0000 (02:12 +0200)
commit41d44ac7a61e2f74453af40d4fe1b82af9ea0ada
treeae670b683dc4ab84f0b6185402285a75dad703dc
parent594d905195024b228c962627ae5ae7c17bd582a4
ovpn: fix NULL dereference when killing missing key

ovpn_crypto_kill_key assumes both crypto slots are populated and
dereferences each slot before checking it. That is not guaranteed: a
peer can have only one installed key, and the kill path may be asked to
remove a key that is not present.

Read each slot once while holding the crypto state lock, check for NULL
before looking at key_id, and only replace the slot that actually
matches.

Fixes: 89d3c0e4612a ("ovpn: kill key and notify userspace in case of IV exhaustion")
Signed-off-by: Ralf Lici <ralf@mandelbit.com>
Signed-off-by: Antonio Quartulli <antonio@openvpn.net>
drivers/net/ovpn/crypto.c