VDB

CVE-2026-31678

CVE-2026-31678 PUBLISHED

In the Linux kernel, the following vulnerability has been resolved: openvswitch: defer tunnel netdev_put to RCU release ovs_netdev_tunnel_destroy() may run after NETDEV_UNREGISTER already detached the device. Dropping the netdev reference in destroy can race with concurrent readers that still observe vport->dev. Do not release vport->dev in ovs_netdev_tunnel_destroy(). Instead, let vport_netdev_free() drop the reference from the RCU callback, matching the non-tunnel destroy path and avoiding additional synchronization under RTNL.

EPSS 0.01% · 2.7th percentile

Risk Scores

EPSS Score
0.01%
2.7th percentile

Affected Products

VendorProductVersions
LinuxLinux0, 6.6.131, 6.12.80
linuxlinux_kernel4.3, 4.3, 4.3

Timeline

  • Apr 25, 2026 CVE Published
  • Apr 27, 2026 Security Advisory
  • May 18, 2026 EPSS Score
  • May 19, 2026 EPSS Score
  • May 20, 2026 EPSS Score
  • May 21, 2026 EPSS Score
  • May 22, 2026 EPSS Score
  • May 23, 2026 EPSS Score
  • May 24, 2026 EPSS Score
  • May 25, 2026 EPSS Score
  • May 26, 2026 EPSS Score
  • May 27, 2026 EPSS Score

References

…and 53 more

Open in Interactive Console →
$ Console Community · 100/wk Open console ›