Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/ipoib: Drain RCU callbacks during module teardown

IPoIB reclamation completions can be signaled from inside an RCU callback.
Teardown can wake before the callback returns and unload ib_ipoib while its
code is still executing.

Client registration failure can also remove already-added devices and queue
callbacks. Wait after client and workqueue teardown.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Potential Remote Code Execution via kernel crash
Action: Immediate Patch
AI Analysis

Impact

The RDMA/ipoib driver in the Linux kernel contains a flaw that permits a callback scheduled under the RCU synchronization mechanism to be executed while the module is still unloading. When the kernel wakes before the callback completes, the driver may reference memory that it has already been freed, leading to a use‑after‑free situation that can result in a kernel crash or, in the worst case, arbitrary code execution as part of the kernel.

Affected Systems

All Linux kernel releases that include the RDMA/ipoib driver are potentially affected; the exact affected versions are not specified in the CVE data, so the issue should be considered for all kernels that have not applied the relevant patch from the kernel maintainers.

Risk and Exploitability

The EPSS score indicates a very low probability of exploitation, but the vulnerability is not currently listed in the CISA KEV catalog. The CVSS score is not provided, however the nature of the flaw—use‑after‑free in the kernel—implies a high impact score if exploited. A local privileged attacker can trigger the flaw by unloading the module while an RCU callback is pending, potentially causing a denial of service or execution of arbitrary code. The attack vector is inferred as local, requiring the ability to unload kernel modules or interfere with RDMA operations.

Generated by OpenCVE AI on September 19, 2026 at 07:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a patched release that addresses the RCU callback draining issue
  • If a kernel update is not immediately possible, disable the RDMA/ipoib module by removing or blacklisting it from the boot configuration
  • Verify that no other modules rely on RDMA/ipoib functionality before disabling it, or reconfigure system components to avoid using RDMA if the module must remain unloaded

Generated by OpenCVE AI on September 19, 2026 at 07:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/ipoib: Drain RCU callbacks during module teardown IPoIB reclamation completions can be signaled from inside an RCU callback. Teardown can wake before the callback returns and unload ib_ipoib while its code is still executing. Client registration failure can also remove already-added devices and queue callbacks. Wait after client and workqueue teardown.
Title RDMA/ipoib: Drain RCU callbacks during module teardown
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:18.455Z

Reserved: 2026-09-17T16:02:15.085Z

Link: CVE-2026-93108

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:05.190

Modified: 2026-09-17T17:18:05.190

Link: CVE-2026-93108

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T16:15:13Z

Weaknesses