Affects the Linux kernel, a core component used across organizations; exploit can cause kernel-level compromise or crash and should be prioritized.
CVE-2026-80753
Linux kernel ovpn workqueue bug allows kernel use-after-free, risking system compromise.
Is CVE-2026-80753 being exploited?
Not confirmed. CVE-2026-80753 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.13% probability of exploitation in the next 30 days.
How severe is CVE-2026-80753?
CVE-2026-80753 is rated High with a CVSS score of 8.4. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-80753?
Yes. A fix has been recorded for CVE-2026-80753. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-80753 affect?
CVE-2026-80753 affects Linux kernel (ovpn module), Distributions shipping vulnerable kernels, Devices/VMs using affected kernels. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-80753?
Apply vendor kernel updates and reboot affected hosts immediately
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Kernel use-after-free in ovpn workqueue allowing kernel crash, local privilege escalation or arbitrary kernel code execution via crafted netlink/network activity.
Patch when possible
- affected>= 11851cbd60ea1e5abbd97619d69845ead99303d6 and < b5fe67111e63a8a81ec31056c4475509076fd266
- affected>= 11851cbd60ea1e5abbd97619d69845ead99303d6 and < bbe81f40582d451ac849b20707784220f33a23bd
- affected>= 11851cbd60ea1e5abbd97619d69845ead99303d6 and < e9714db8041763f59dde152c812b96b3de05c6d9
- affected6.16
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.