SB20260918104 - Use-after-free in Linux kernel hw mlx5 driver
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-93109)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a failure to wait for queued RCU callbacks in mlx5_ib module teardown when closing a DevX event file or detaching auxiliary driver devices. A local user can close a DevX event file to cause a denial of service.
The issue can also occur during registration error unwinding after driver registration attaches existing devices before failing.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/2f946e7839f677fa14574b6babad14b37ae0bbbe
- https://git.kernel.org/stable/c/4664368b9bd9d5d79ebad24056b98c34b9fed20f
- https://git.kernel.org/stable/c/4be7810ba70291abb2f68cc6db0ae1b93ee9c76a
- https://git.kernel.org/stable/c/59d60e04afd012f07e996d2e34cb90a4ec6f5cff
- https://git.kernel.org/stable/c/7babc25d8dd5b7642920fbc0737cfd1469e7025b
- https://git.kernel.org/stable/c/ca428e597f12b278bf158356e34641e6386cfa82
- https://git.kernel.org/stable/c/e37cdd75f8d61c1123d324ae5667ac3da562290e