CVE-2026-93279

Source
https://cve.org/CVERecord?id=CVE-2026-93279
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93279.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93279
Downstream
Published
2026-09-24T15:52:21Z
Modified
2026-09-25T03:48:54Z
Summary
staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown
Details

In the Linux kernel, the following vulnerability has been resolved:

staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown

The TX cleanup tasklet can be scheduled by the watchdog IRQ handler to execute cvm_oct_tx_do_cleanup. There can be a pending tasklet in the queue which might run after the cvm_oct_remove() frees net_device structures, causing a use-after-free in cvm_oct_tx_do_cleanup() as it iterates cvm_oct_device[] which is an array of netdevice pointers. Add tasklet_kill() after free_irq() to ensure the tasklet is no longer scheduled or running before teardown proceeds.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93279.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4898c560103fb8075c10a8e9d70e0ca26873075e
Fixed
32efcb6d5f4e3f030e7b0a3ba5c6c0684dd07486
Fixed
d15226338dfaa84ffff142d32723cdf74d0c47c4
Fixed
a77efd85e0d48c877f66d2bc3ab89cc1b8dacd19
Fixed
b6365e4186322858a82c8713b1d0bd209c8e765a
Fixed
03d12490afd1198310ad0aba42462329832eb739
Fixed
2c0c9956596e48654bb4855e2a0742748a0826a7
Fixed
41a79bd9e5a74f8f483b3b206d10567912874fb4
Fixed
b9af44b0d20b2247c4eb0ea5cfca907d643eea50

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93279.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.34
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93279.json"