CVE-2026-93278

Summary

In the Linux kernel, the following vulnerability has been resolved:

staging: octeon: add missing napi_disable in cvm_oct_rx_shutdown

cvm_oct_rx_shutdown calls free_irq and netif_napi_del without disabling the napi instance first. As the free_irq only waits for completion of hard interrupt handlers, the napi poll function could still be active. If cvm_oct_remove proceeds to free the plat structure (which holds the NAPI instances), the active poll function will access freed memory, resulting in a use-after-free crash.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux3368c784bcf77124aaf39372e627016c36bd4472 < 158389d7af04bbf0664d91c2ce31fcc9eeace1ebaffected
LinuxLinux3368c784bcf77124aaf39372e627016c36bd4472 < c124049c3a7006fd6caf629139a5722610bbffb4affected
LinuxLinux3368c784bcf77124aaf39372e627016c36bd4472 < 98f9036b2254c928cb44da0c77dba38f66f7d8f1affected
LinuxLinux3368c784bcf77124aaf39372e627016c36bd4472 < b38fbd68cc36b4f478a1e3cfc169b8616ae1337daffected
LinuxLinux3368c784bcf77124aaf39372e627016c36bd4472 < 89f9f433271fad9351de6a3c713b45b2cfb23e4aaffected
LinuxLinux3368c784bcf77124aaf39372e627016c36bd4472 < b2243ffaac14cc3639b5b32a371aac37f96ee554affected
LinuxLinux3368c784bcf77124aaf39372e627016c36bd4472 < c0a9a8586a63fda49e61a6b83360feac2a60d898affected
LinuxLinux2.6.34affected
LinuxLinux0 < 2.6.34unaffected
LinuxLinux5.15.221 <= 5.15.*unaffected
LinuxLinux6.1.188 <= 6.1.*unaffected
LinuxLinux6.6.157 <= 6.6.*unaffected
LinuxLinux6.12.110 <= 6.12.*unaffected
LinuxLinux6.18.52 <= 6.18.*unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References