Use-after-free in Linux kernel - CVE-2026-93278
Published: September 25, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in cvm_oct_rx_shutdown when removing the platform device while a NAPI poll function remains active. A local user can trigger the vulnerable shutdown sequence while a NAPI poll function remains active to cause a denial of service.
Affected software
How to mitigate CVE-2026-93278
External References
- https://git.kernel.org/stable/c/158389d7af04bbf0664d91c2ce31fcc9eeace1eb
- https://git.kernel.org/stable/c/89f9f433271fad9351de6a3c713b45b2cfb23e4a
- https://git.kernel.org/stable/c/98f9036b2254c928cb44da0c77dba38f66f7d8f1
- https://git.kernel.org/stable/c/b2243ffaac14cc3639b5b32a371aac37f96ee554
- https://git.kernel.org/stable/c/b38fbd68cc36b4f478a1e3cfc169b8616ae1337d
- https://git.kernel.org/stable/c/c0a9a8586a63fda49e61a6b83360feac2a60d898
- https://git.kernel.org/stable/c/c124049c3a7006fd6caf629139a5722610bbffb4