CVE-2026-93278
Description
In the Linux kernel, the following vulnerability has been resolved: staging: octeon: add missing napi_disable in cvm_oct_rx_shutdown cvm_oct_rx_shutdown calls free_irq and netif_napi_del without disabling the napi instance first. As the free_irq only waits for completion of hard interrupt handlers, the napi poll function could still be active. If cvm_oct_remove proceeds to free the plat structure (which holds the NAPI instances), the active poll function will access freed memory, resulting in a use-after-free crash.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
References
- https://git.kernel.org/stable/c/158389d7af04bbf0664d91c2ce31fcc9eeace1eb
- https://git.kernel.org/stable/c/89f9f433271fad9351de6a3c713b45b2cfb23e4a
- https://git.kernel.org/stable/c/98f9036b2254c928cb44da0c77dba38f66f7d8f1
- https://git.kernel.org/stable/c/b2243ffaac14cc3639b5b32a371aac37f96ee554
- https://git.kernel.org/stable/c/b38fbd68cc36b4f478a1e3cfc169b8616ae1337d
- https://git.kernel.org/stable/c/c0a9a8586a63fda49e61a6b83360feac2a60d898
- https://git.kernel.org/stable/c/c124049c3a7006fd6caf629139a5722610bbffb4
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.