CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's OpenVPN implementation, specifically in the `ovpn_crypto_kill_key` function, which improperly assumes that both crypto slots are populated. This can lead to a NULL dereference when attempting to remove a key that may not be present, potentially causing a denial of service. Linux system administrators and developers using OpenVPN should prioritize this issue to mitigate risks associated with system stability and security.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: ovpn: fix NULL dereference when killing missing key ovpn_crypto_kill_key assumes both crypto slots are populated and dereferences each slot before checking it. That is not guaranteed: a peer can have only one installed key, and the kill path may be asked to remove a key that is not present. Read each slot once while holding the crypto state lock, check for NULL before looking at key_id, and only replace the slot that actually matches.