CVE-2026-93109

Source
https://cve.org/CVERecord?id=CVE-2026-93109
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93109.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93109
Downstream
Published
2026-09-17T16:11:19Z
Modified
2026-09-19T03:47:31Z
Summary
RDMA/mlx5: Drain RCU callbacks during module teardown
Details

In the Linux kernel, the following vulnerability has been resolved:

RDMA/mlx5: Drain RCU callbacks during module teardown

devx_free_subscription() can remain queued after the last DevX event file drops its module reference or an auxiliary driver detaches its devices. mlx5_ib can then unload before the callback runs.

Registration error unwind has the same risk because driver registration can attach existing devices before failing. Wait after all drivers have stopped.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93109.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6898d1c661d79f4707d8ba82991b2195822780ca
Fixed
ca428e597f12b278bf158356e34641e6386cfa82
Fixed
59d60e04afd012f07e996d2e34cb90a4ec6f5cff
Fixed
2f946e7839f677fa14574b6babad14b37ae0bbbe
Fixed
4be7810ba70291abb2f68cc6db0ae1b93ee9c76a
Fixed
7babc25d8dd5b7642920fbc0737cfd1469e7025b
Fixed
4664368b9bd9d5d79ebad24056b98c34b9fed20f
Fixed
e37cdd75f8d61c1123d324ae5667ac3da562290e

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93109.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.6.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93109.json"