Bug 2461761 (CVE-2026-31678) - CVE-2026-31678 kernel: openvswitch: defer tunnel netdev_put to RCU release
Summary: CVE-2026-31678 kernel: openvswitch: defer tunnel netdev_put to RCU release
Keywords:
Status: NEW
Alias: CVE-2026-31678
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-04-25 09:01 UTC by OSIDB Bzimport
Modified: 2026-09-03 11:39 UTC (History)
18 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-04-25 09:01:48 UTC
In the Linux kernel, the following vulnerability has been resolved:

openvswitch: defer tunnel netdev_put to RCU release

ovs_netdev_tunnel_destroy() may run after NETDEV_UNREGISTER already
detached the device. Dropping the netdev reference in destroy can race
with concurrent readers that still observe vport->dev.

Do not release vport->dev in ovs_netdev_tunnel_destroy(). Instead, let
vport_netdev_free() drop the reference from the RCU callback, matching
the non-tunnel destroy path and avoiding additional synchronization
under RTNL.

Comment 4 Akiyoshi Kurita 2026-09-03 04:34:44 UTC
A public exploit for CVE-2026-31678 has been released.

Red Hat CVE database:
https://access.redhat.com/security/cve/cve-2026-31678

Public exploit:
https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-31678-Fedora-6.19.10-300

Demo video:
https://x.com/cybermeowfia/status/2095362685227667767

Reference patches:

RHEL 7 through RHEL 9:
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=9d56aced21fb9c104e8a3f3be9b21fbafe448ffc

RHEL 10:
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=bbe7bd722bfaea36aab3da6cc60fb4a05c644643

Possible mitigation:
Prevent the openvswitch kernel module from being loaded.

Example:
echo "install openvswitch /bin/true" > /etc/modprobe.d/disable-openvswitch.conf

Please review whether the public exploit changes the impact or priority assessment for affected RHEL releases.


Note You need to log in before you can comment on or make changes to this bug.