cbcvebase.
CVE-2026-31508
published 2026-04-22

CVE-2026-31508: In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: Avoid releasing netdev before teardown completes The patch cited in the…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
2.9th percentile
In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: Avoid releasing netdev before teardown completes The patch cited in the Fixes tag below changed the teardown code for OVS ports to no longer unconditionally take the RTNL. After this change, the netdev_destroy() callback can proceed immediately to the call_rcu() invocation if the IFF_OVS_DATAPATH flag is already cleared on the netdev. The ovs_netdev_detach_dev() function clears the flag before completing the unregistration, and if it gets preempted after clearing the flag (as can happen on an -rt kernel), netdev_destroy() can complete and the device can be freed before the unregistration completes. This leads to a splat like: [ 998.393867] Oops: general protection fault, probably for non-canonical address 0xff00000001000239: 0000 [#1] SMP PTI [ 998.393877] CPU: 42 UID: 0 PID: 55177 Comm: ip Kdump: loaded Not tainted 6.12.0-211.1.1.el10_2.x86_64+rt #1 PREEMPT_RT [ 998.393886] Hardware name: Dell Inc. PowerEdge R740/0JMK61, BIOS 2.24.0 03/27/2025 [ 998.393889] RIP: 0010:dev_set_promiscuity+0x8d/0xa0 [ 998.393901] Code: 00 00 75 d8 48 8b 53 08 48 83 ba b0 02 00 00 00 75 ca 48 83 c4 08 5b c3 cc cc cc cc 48 83 bf 48 09 00 00 00 75 91 48 8b 47 08 83 b8 b0 02 00 00 00 74 97 eb 81 0f 1f 80 00 00 00 00 90 90 90 [ 998.393906] RSP: 0018:ffffce5864a5f6a0 EFLAGS: 00010246 [ 998.393912] RAX: ff00000000ffff89 RBX: ffff894d0adf5a05 RCX: 0000000000000000 [ 998.393917] RDX: 0000000000000000 RSI: 00000000ffffffff RDI: ffff894d0adf5a05 [ 998.393921] RBP: ffff894d19252000 R08: ffff894d19252000 R09: 0000000000000000 [ 998.393924] R10: ffff894d19252000 R11: ffff894d192521b8 R12: 0000000000000006 [ 998.393927] R13: ffffce5864a5f738 R14: 00000000ffffffe2 R15: 0000000000000000 [ 998.393931] FS: 00007fad61971800(0000) GS:ffff894cc0140000(0000) knlGS:0000000000000000 [ 998.393936] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 998.393940] CR2: 000055df0a2a6e40 CR3: 000000011c7fe003 CR4: 00000000007726

Affected

25 ranges
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 052e5db5be4576e0a8ef1460b210da5f328f4cd1 < 33609454be4f582e686a4bf13d4482a5ca0f6c4b33609454be4f582e686a4bf13d4482a5ca0f6c4b
linuxlinux>= 0fc642f011cb7a7eff41109e66d3b552e9f4d795 < 4c3e25a7b711a402fcbbbcfbbdf2868ece1ae7c84c3e25a7b711a402fcbbbcfbbdf2868ece1ae7c8
linuxlinux>= 5.10.248 < 5.10.2535.10.253
linuxlinux>= 5.15.198 < 5.15.2035.15.203
linuxlinux>= 5116f61ab11846844585c9082c547c4ccd97ff1a < 43579baa17270aa51f93eb09b6e4af6e047b7f6e43579baa17270aa51f93eb09b6e4af6e047b7f6e
linuxlinux>= 5498227676303e3ffa9a3a46214af96bc3e81314 < 755a6300afbd743cda4b102f24f343380ec0e0ff755a6300afbd743cda4b102f24f343380ec0e0ff
linuxlinux>= 5498227676303e3ffa9a3a46214af96bc3e81314 < 7c770dadfda5cbbde6aa3c4363ed513f1d212bf87c770dadfda5cbbde6aa3c4363ed513f1d212bf8
linuxlinux>= 6.1.160 < 6.1.1686.1.168
linuxlinux>= 6.12.64 < 6.12.806.12.80
linuxlinux>= 6.18.4 < 6.18.216.18.21
linuxlinux>= 6.6.120 < 6.6.1316.6.131
linuxlinux>= b823c3344d5446b720227ba561df10a4f0add515 < df3c95be76103604e752131d9495a24814915ecedf3c95be76103604e752131d9495a24814915ece
linuxlinux>= c98263d5ace597c096a7a60aeef790da7b54979e < 5fdeaf591a0942772c2d18ff3563697a49ad01c65fdeaf591a0942772c2d18ff3563697a49ad01c6
linuxlinux>= f31557fb1b35332cca9994aa196cef284bcf3807 < 95265232b49765a4d00f4d028c100bb7185600f495265232b49765a4d00f4d028c100bb7185600f4
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 5.10.248 < 5.10.2535.10.253
linuxlinux_kernel>= 5.15.198 < 5.15.2035.15.203
linuxlinux_kernel>= 6.1.160 < 6.1.1686.1.168
linuxlinux_kernel>= 6.12.64 < 6.12.806.12.80
linuxlinux_kernel>= 6.18.4 < 6.18.216.18.21
linuxlinux_kernel>= 6.19.1 < 6.19.116.19.11
linuxlinux_kernel>= 6.6.120 < 6.6.1316.6.131

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.