PT-2026-35138 · Linux · Linux Kernel

Published

2026-04-25

·

Updated

2026-06-15

·

CVE-2026-31678

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A race condition exists in the Open vSwitch component of the Linux kernel. The ovs netdev tunnel destroy() function may execute after the NETDEV UNREGISTER process has already detached the device. Releasing the netdev reference during the destroy process can conflict with concurrent readers that still observe vport->dev.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-31678
ECHO-78CB-C86F-9F8E
OESA-2026-2579
OESA-2026-2580
OESA-2026-2581
SUSE-SU-2026:22108-1

Affected Products

Linux Kernel