Description
In the Linux kernel, the following vulnerability has been resolved:

octeontx2-vf: fix workqueue and netdev race in probe/remove

Initialize the VF workqueue before register_netdev() so ndo_set_rx_mode
does not queue work on a NULL workqueue. Unregister the netdev before
destroying the workqueue, and add proper probe error cleanup.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via kernel crash due to a race condition
Action: Immediate Patch
AI Analysis

Impact

A race condition exists in the Linux kernel driver octeontx2-vf during the probe and removal phases. The driver initializes a workqueue after registering the network device, so if ndo_set_rx_mode queues work before the workqueue is ready, the kernel may attempt to execute a task on a NULL workqueue, leading to a kernel panic. The resulting crash denies service to the entire system.

Affected Systems

Systems running the Linux kernel that load the octeontx2-vf driver are affected. No specific kernel versions are enumerated in the available data, so the vulnerability applies to all deployments that include this driver.

Risk and Exploitability

The EPSS score is less than 1%, indicating a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The lack of a public CVSS score limits precise severity quantification, but kernel crashes are high impact. The likely attack vector is local; an attacker with sufficient privileges to influence the driver’s probe or removal sequence could trigger the crash, resulting in a denial‑of‑service.

Generated by OpenCVE AI on September 20, 2026 at 04:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the octeontx2-vf workqueue and netdev race fix.
  • If an update is not available, prevent the octeontx2-vf driver from loading by disabling it via modprobe.d or blacklist configuration.
  • Continue to monitor kernel release notes for the inclusion of the patch and apply it promptly when it becomes available.

Generated by OpenCVE AI on September 20, 2026 at 04:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: octeontx2-vf: fix workqueue and netdev race in probe/remove Initialize the VF workqueue before register_netdev() so ndo_set_rx_mode does not queue work on a NULL workqueue. Unregister the netdev before destroying the workqueue, and add proper probe error cleanup.
Title octeontx2-vf: fix workqueue and netdev race in probe/remove
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:00.839Z

Reserved: 2026-09-11T19:38:34.785Z

Link: CVE-2026-90084

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:16:57.847

Modified: 2026-09-17T17:16:57.847

Link: CVE-2026-90084

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:00:13Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-476

    NULL Pointer Dereference