PT-2026-97965 · Linux · Linux Kernel

CVE-2026-93278

·

Published

2026-09-24

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free crash occurs in the octeon staging driver. The cvm oct rx shutdown() function calls free irq() and netif napi del() without first disabling the NAPI instance. Since free irq() only waits for hard interrupt handlers to complete, the NAPI poll function may remain active. If cvm oct remove() subsequently frees the plat structure containing the NAPI instances, the active poll function accesses freed memory. NAPI (New API) is a mechanism used by the Linux kernel to reduce the number of interrupts by switching to a polling mode during high network traffic.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-93278

Affected Products

Linux Kernel