Answer in brief
CVE-2026-93278 records a Unknown severity vulnerability in staging: octeon: add missing napi_disable in cvm_oct_rx_shutdown. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=3368c784bcf77124aaf39372e627016c36bd4472 <158389d7af04bbf0664d91c2ce31fcc9eeace1eb || >=3368c784bcf77124aaf39372e627016c36bd4472 <c124049c3a7006fd6caf629139a5722610bbffb4 || >=3368c784bcf77124aaf39372e627016c36bd4472 <98f9036b2254c928cb44da0c77dba38f66f7d8f1 || >=3368c784bcf77124aaf39372e627016c36bd4472 <b38fbd68cc36b4f478a1e3cfc169b8616ae1337d || >=3368c784bcf77124aaf39372e627016c36bd4472 <89f9f433271fad9351de6a3c713b45b2cfb23e4a || >=3368c784bcf77124aaf39372e627016c36bd4472 <b2243ffaac14cc3639b5b32a371aac37f96ee554 || >=3368c784bcf77124aaf39372e627016c36bd4472 <c0a9a8586a63fda49e61a6b83360feac2a60d898 | 158389d7af04bbf0664d91c2ce31fcc9eeace1eb, c124049c3a7006fd6caf629139a5722610bbffb4, 98f9036b2254c928cb44da0c77dba38f66f7d8f1, b38fbd68cc36b4f478a1e3cfc169b8616ae1337d, 89f9f433271fad9351de6a3c713b45b2cfb23e4a, b2243ffaac14cc3639b5b32a371aac37f96ee554, c0a9a8586a63fda49e61a6b83360feac2a60d898 |
| Linux/Linuxgeneric | 2.6.34 | Not reported |
Published upstream
Sep 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 25, 2026
In the Linux kernel, the following vulnerability has been resolved: staging: octeon: add missing napi_disable in cvm_oct_rx_shutdown cvm_oct_rx_shutdown calls free_irq and netif_napi_del without disabling the napi instance first. As the free_irq only waits for completion of hard interrupt handlers, the napi poll function could still be active. If cvm_oct_remove proceeds to free the plat structure (which holds the NAPI instances), the active poll function will access freed memory, resulting in a use-after-free crash.
Quoted source text, attributed separately from HOL analysis.