CVE Database
/

CVE-2026-31678

Back to search

CVE-2026-31678

Published: Apr 25, 2026

Modified: May 11, 2026

PUBLISHED

CVSS v3.1

7.8

HIGH

Description

In the Linux kernel, the following vulnerability has been resolved: openvswitch: defer tunnel netdev_put to RCU release ovs_netdev_tunnel_destroy() may run after NETDEV_UNREGISTER already detached the device. Dropping the netdev reference in destroy can race with concurrent readers that still observe vport->dev. Do not release vport->dev in ovs_netdev_tunnel_destroy(). Instead, let vport_netdev_free() drop the reference from the RCU callback, matching the non-tunnel destroy path and avoiding additional synchronization under RTNL.

VendorProductVersions

Linux

Linux

affected
a9020fde67a6eb77f8130feff633189f99264db1 - < 9d56aced21fb9c104e8a3f3be9b21fbafe448ffc
affected
a9020fde67a6eb77f8130feff633189f99264db1 - < 42f0d3d81209654c08ffdde5a34b9b92d2645896
affected
a9020fde67a6eb77f8130feff633189f99264db1 - < bbe7bd722bfaea36aab3da6cc60fb4a05c644643
affected
a9020fde67a6eb77f8130feff633189f99264db1 - < 98b726ab5e2a4811e27c28e4d041f75bba147eab
affected
a9020fde67a6eb77f8130feff633189f99264db1 - < b8c56a3fc5d879c0928f207a756b0f067f06c6a8

+1 more versions

Linux

Linux

affected
4.3
unaffected
0 - < 4.3
unaffected
6.1.168 - <= 6.1.*
unaffected
6.6.131 - <= 6.6.*
unaffected
6.12.80 - <= 6.12.*

+3 more versions

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Local

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now