CVE 7.8 HIGH

openvswitch: defer tunnel netdev_put to RCU release_CVE-2026-31678

7.8 / 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

In the Linux kernel, the following vulnerability has been resolved:

openvswitch: defer tunnel netdev_put to RCU release

ovs_netdev_tunnel_destroy() may run after NETDEV_UNREGISTER already
detached the device. Dropping the netdev reference in destroy can race
with concurrent readers that still observe vport->dev.

Do not release vport->dev in ovs_netdev_tunnel_destroy(). Instead, let
vport_netdev_free() drop the reference from the RCU callback, matching
the non-tunnel destroy path and avoiding additional synchronization
under RTNL.

Basic Information

ID CVE-2026-31678
Source Linux
Published Apr 25, 2026 at 08:46
Modified Apr 27, 2026 at 14:04

Affected Product

Vendor Linux
Product Linux
Version a9020fde67a6eb77f8130feff633189f99264db1
Affected Versions Linux Linux a9020fde67a6eb77f8130feff633189f99264db1
Linux Linux a9020fde67a6eb77f8130feff633189f99264db1
Linux Linux a9020fde67a6eb77f8130feff633189f99264db1
Linux Linux a9020fde67a6eb77f8130feff633189f99264db1
Linux Linux a9020fde67a6eb77f8130feff633189f99264db1
Linux Linux a9020fde67a6eb77f8130feff633189f99264db1
Linux Linux 4.3

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.