« Volver al listado

CVE-2026-93278

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

staging: octeon: add missing napi_disable in cvm_oct_rx_shutdown

cvm_oct_rx_shutdown calls free_irq and netif_napi_del without disabling the napi instance first. As the free_irq only waits for completion of hard interrupt handlers, the napi poll function could still be active. If cvm_oct_remove proceeds to free the plat structure (which holds the NAPI instances), the active poll function will access freed memory, resulting in a use-after-free crash.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93278",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3368c784bcf77124aaf39372e627016c36bd4472",
              "lessThan": "158389d7af04bbf0664d91c2ce31fcc9eeace1eb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3368c784bcf77124aaf39372e627016c36bd4472",
              "lessThan": "c124049c3a7006fd6caf629139a5722610bbffb4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3368c784bcf77124aaf39372e627016c36bd4472",
              "lessThan": "98f9036b2254c928cb44da0c77dba38f66f7d8f1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3368c784bcf77124aaf39372e627016c36bd4472",
              "lessThan": "b38fbd68cc36b4f478a1e3cfc169b8616ae1337d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3368c784bcf77124aaf39372e627016c36bd4472",
              "lessThan": "89f9f433271fad9351de6a3c713b45b2cfb23e4a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3368c784bcf77124aaf39372e627016c36bd4472",
              "lessThan": "b2243ffaac14cc3639b5b32a371aac37f96ee554",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3368c784bcf77124aaf39372e627016c36bd4472",
              "lessThan": "c0a9a8586a63fda49e61a6b83360feac2a60d898",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/staging/octeon/ethernet-rx.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.34"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "2.6.34",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/staging/octeon/ethernet-rx.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-24T16:17:25.017",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/158389d7af04bbf0664d91c2ce31fcc9eeace1eb",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/89f9f433271fad9351de6a3c713b45b2cfb23e4a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/98f9036b2254c928cb44da0c77dba38f66f7d8f1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b2243ffaac14cc3639b5b32a371aac37f96ee554",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b38fbd68cc36b4f478a1e3cfc169b8616ae1337d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c0a9a8586a63fda49e61a6b83360feac2a60d898",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c124049c3a7006fd6caf629139a5722610bbffb4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: octeon: add missing napi_disable in cvm_oct_rx_shutdown\n\ncvm_oct_rx_shutdown calls free_irq and netif_napi_del without\ndisabling the napi instance first. As the free_irq only waits\nfor completion of hard interrupt handlers, the napi poll\nfunction could still be active. If cvm_oct_remove proceeds to\nfree the plat structure (which holds the NAPI instances), the\nactive poll function will access freed memory, resulting in a\nuse-after-free crash."
    }
  ],
  "lastModified": "2026-09-24T16:17:25.017",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}