{"apiVersion":"1.0","identifier":"CVE-2026-80520","description":"In the Linux kernel, the following vulnerability has been resolved: ovpn: fix NULL dereference when killing missing key ovpn_crypto_kill_key assumes both crypto slots are populated and dereferences each slot before checking it. That is not guaranteed: a peer can have only one installed key, and the kill path may be asked to remove a key that is not present. Read each slot once while holding the crypto state lock, check for NULL before looking at key_id, and only replace the slot that actually matches.","publishedAt":"2026-08-26T15:17:05","lastModifiedAt":"2026-08-27T06:17:30","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-80520","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","epssProbability":0.00432,"riskScore":0.78,"affectedProduct":"Linux kernel","affectedVersions":"unknown","vulnerabilityType":"Kernel","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-80520","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-80520","en":"https://www.redsauce.net/en/cves/CVE-2026-80520","fr":"https://www.redsauce.net/fr/cves/CVE-2026-80520","pt":"https://www.redsauce.net/pt/cves/CVE-2026-80520","de":"https://www.redsauce.net/de/cves/CVE-2026-80520","sk":"https://www.redsauce.net/sk/cves/CVE-2026-80520","el":"https://www.redsauce.net/el/cves/CVE-2026-80520"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-80520"}}