CVE-2026-31678Patch(linux / linux_kernel)

HIGHCVSS 7.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch linux linux_kernel systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: openvswitch: defer tunnel netdev_put to RCU release ovs_netdev_tunnel_destroy() may run after NETDEV_UNREGISTER already detached the device. Dropping the netdev reference in destroy can race with concurrent readers that still observe vport->dev. Do not release vport->dev in ovs_netdev_tunnel_destroy(). Instead, let vport_netdev_free() drop the reference from the RCU callback, matching the non-tunnel destroy path and avoiding additional synchronization under RTNL.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-367

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 7 mentions across 5 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 5 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 6 signals
  • General: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-04-25); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-04-25: 2Mentions · 2026-09-03: 2Mentions · 2026-09-04: 1Mentions · 2026-09-12: 1Mentions · 2026-09-15: 1PoC Mentioned / Linked · 2026-09-03: 2PoC Mentioned / Linked · 2026-09-04: 1PoC Mentioned / Linked · 2026-09-12: 1PoC Mentioned / Linked · 2026-09-15: 1Exploit Tool / Code · 2026-09-03: 2Exploit Tool / Code · 2026-09-04: 1Active Exploitation · 2026-09-12: 1Patch / Workaround · 2026-04-25: 2Patch / Workaround · 2026-09-03: 1Patch / Workaround · 2026-09-04: 1Patch / Workaround · 2026-09-15: 1Technical Details · 2026-04-25: 1Technical Details · 2026-09-03: 2Technical Details · 2026-09-04: 1Technical Details · 2026-09-12: 1Technical Details · 2026-09-15: 104-2509-0309-0409-1209-15
Signal classification3 categories
Patch
342.9%
Exploit
342.9%
General
114.3%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-04-252
Patch2
2026-09-032
Exploit2
2026-09-041
Exploit1
2026-09-121
General1
2026-09-151
Patch1
Full discourse7 posts
  • Cyber Meowfia@cybermeowfia
    Exploit

    Today's exploit is for the latest Fedora, a UAF in openvswitch: CVE-2026-31678. It was introduced in Aug 2015 and fixed upstream in Mar 2026. Discovered and exploited by the NebuSec security pipeline. Exp source code: https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-31678-Fedora-6.19.10-300 https://t.co/LApCtejKOq

    Post summary

    The post shares a functional exploit for CVE-2026-31678, provides source code, notes the fix upstream, but offers no evidence of active real-world use.

    011147113.3K
    439 followersView on X
  • Mr. OS@ksg93rd
    General

    #Analytics #Threat_Research An analytical review of the main cybersecurity events (Sep 05-12, 2026) 1⃣ Sonicwall SMA1000 Attack https://hunt.io/blog/sonicwall-sma1000-uk-council-attack // CVE-2026-15409 2⃣ Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability https://hunt.io/blog/sonicwall-sma1000-uk-council-attack 3⃣ Next Nightmare Eclipse Vulnerability https://github.com/MSNightmare/ShieldCrash/blob/main/README.md // Microsoft has failed to properly patch ShieldBreak CVE-2026-69414.. 4⃣ FortiPAM Vulnerability https://amibeingpwned.com/blog/fortinet-pam-vuln // CVE-2026-84388 5⃣ Researchers from Nebula Security have disclosed 18 vulnerabilities in the Linux kernel https://www.openwall.com/lists/oss-security/2026/09/08/1 // CVE-2026-80714, CVE-2026-74597, CVE-2026-74581, CVE-2026-74480, CVE-2026-72255, CVE-2026-72137, CVE-2026-68376, CVE-2026-68162, CVE-2026-64560,  CVE-2026-63834, CVE-2026-52933, CVE-2026-52929, CVE-2026-52924, CVE-2026-52923, CVE-2026-52912, CVE-2026-43501, CVE-2026-43502, CVE-2026-43074, CVE-2026-43042, CVE-2026-31678, CVE-2026-31659, CVE-2026-23274 6⃣ Netscaler ADC Exploit 7⃣ Critical vulnerabilities in MikroTik RouterOS https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/ 8⃣ GRAYRABBIT One-click backdoor // One click. Three critical failures. One backdoor https://www.gendigital.com/blog/insights/research/one-click-backdoor-sogou 9⃣ Attacks using browser-in-browser (BiTB) phishing techniques https://www.huntress.com/blog/phishing-bitb-rmm-attacks 🔟 Beltdown: Escaping the Claude Code sandbox https://www.accomplish.ai/blog/beltdown-escaping-the-claude-code-sandbox/ // An untrusted repository opened in Claude Code can escape the macOS sandbox and run commands on your computer as your privileged user http://www.Geniebot.pro http://www.cyberpocket.org

    Post summary

    The post serves as a concise weekly roundup of various cybersecurity incidents, citing multiple CVEs and related links, with a notable mention of active exploitation in MikroTik RouterOS but without detailed exploit code or patch information.

    01052600
    3.4K followersView on X
  • !Manan@0xManan
    Exploit

    New exploit repo: CVE-2026-31678 (openvswitch UAF) for Fedora. The point of a public drop like this is operational: you get real code and a target environment, not just theory. If you run OVS on Fedora kernels in the repo’s lane, patch ASAP. https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-31678-Fedora-6.19.10-300

    Post summary

    A GitHub repository hosts a functional exploit for CVE‑2026‑31678, a use‑after‑free flaw in Open vSwitch on Fedora, and the post urges users to apply a patch.

    00030289
    2.2K followersView on X
  • Threat Landscape@LandscapeThreat
    Patch

    Researchers disclosed CVE-2026-43502, a Linux kernel local privilege-escalation vulnerability in the RDS zerocopy send path, alongside 20 additional exploitable Linux bugs. - An unprivileged local user can obtain root privileges without Linux capabilities or user namespaces when required networking, asynchronous I/O, and RDS components are enabled. - The vulnerability affects kernels from Linux v4.17 and was demonstrated on openSUSE with kernel 6.4.0-150600.23.100. - The issue was fixed by commit 44b550d88b26, first included in Linux v7.1-rc3; public exploits for the listed vulnerabilities are available. VULNERABILITY CVE-2026-23274 CVE-2026-31659 CVE-2026-31678 CVE-2026-43042 CVE-2026-43074 CVE-2026-43501 CVE-2026-43502 CVE-2026-52912 CVE-2026-52923 CVE-2026-52924 CVE-2026-52929 CVE-2026-52933 CVE-2026-63834 CVE-2026-64560 CVE-2026-68162 CVE-2026-68376 CVE-2026-72137 CVE-2026-72255 CVE-2026-74480 CVE-2026-74581 CVE-2026-74597 CVE-2026-80714

    Post summary

    The text announces the disclosure of CVE-2026-43502, a Linux kernel local privilege escalation vulnerability, while highlighting that a fix is available via commit 44b550d88b26 in Linux v7.1-rc3, alongside noting that public exploits exist for these vulnerabilities.

    0002055
    103 followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Exploit

    🔴 NebuSec, Linux kernel'deki Open vSwitch (OVS) bileşeninde bulunan CVE-2026-31678 adlı UAF açığı için çalışan exploit yayınladı. Açık, yerel bir saldırganın kernel seviyesinde ayrıcalıklarını yükseltmesine (LPE) olanak sağlayabiliyor. Etkilenen örnek: Fedora 44 — Linux 6.19.10-300 Açığın kökeni Linux kernel 4.3 dönemine kadar uzanıyor. Upstream'de düzeltme ise 2026'da yayınlandı. NebuSec'in exploit'i: https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-31678-Fedora-6.19.10-300 https://x.com/cybermeowfia/status/2095362685227667767/video/1

    Post summary

    NebuSec published a functional exploit for CVE-2026-31678, an UAF flaw in Open vSwitch that allows local privilege escalation on Fedora 44. The upstream patch was released in 2026, and the exploit code is publicly available.

    10010261
    2.2K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-31678 In the Linux kernel, the following vulnerability has been resolved: openvswitch: defer tunnel netdev_put to RCU release ovs_netdev_tunnel_destroy() may run after NE… https://www.cve.org/CVERecord?id=CVE-2026-31678

    Post summary

    CVE‑2026‑31678 was fixed in the Linux kernel with a patch that defers tunnel netdev_put to RCU release; no PoC, exploit, or active exploitation details are given.

    0100083
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Patch

    CVE-2026-31678 Linux Kernel OpenVSwitch Tunnel Netdev Reference Race Condition Resolution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-31678

    Post summary

    The CVE-2026-31678 concerns a race‑condition bug in Linux Kernel’s OpenVSwitch Tunnel Netdev, and the text indicates that a fix/resolution has been released.

    0000041
    4.0K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more