CVE-2026-93278
Published Sep 24, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: staging: octeon: add missing napi_disable in cvm_oct_rx_shutdown cvm_oct_rx_shutdown calls free_irq and netif_napi_del without disabling the napi instance first. As the free_irq only waits for completion of hard interrupt handlers, the napi poll function could still be active. If cvm_oct_remove proceeds to free the plat structure (which holds the NAPI instances), the active poll function will access freed memory, resulting in a use-after-free crash.
Is your site exposed to CVE-2026-93278?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/158389d7af04bbf0664d91c2ce31fcc9eeace1eb
https://git.kernel.org/stable/c/89f9f433271fad9351de6a3c713b45b2cfb23e4a
https://git.kernel.org/stable/c/98f9036b2254c928cb44da0c77dba38f66f7d8f1
https://git.kernel.org/stable/c/b2243ffaac14cc3639b5b32a371aac37f96ee554
https://git.kernel.org/stable/c/b38fbd68cc36b4f478a1e3cfc169b8616ae1337d
https://git.kernel.org/stable/c/c0a9a8586a63fda49e61a6b83360feac2a60d898
https://git.kernel.org/stable/c/c124049c3a7006fd6caf629139a5722610bbffb4
Frequently Asked Questions
What is CVE-2026-93278? +
In the Linux kernel, the following vulnerability has been resolved:
staging: octeon: add missing napi_disable in cvm_oct_rx_shutdown
cvm_oct_rx_shutdown calls free_irq and netif_napi_del without
disabling the napi instance first. As the free_irq only waits
for completion of hard interrupt handlers, the napi poll
function could still be active. If cvm_oct_remove proceeds to
free the plat structure (which holds the NAPI instances), the
active poll function will access freed memory, resulting in a
use-after-free crash.
How do I check if I'm vulnerable to CVE-2026-93278? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.