Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/mlx5: Drain RCU callbacks during module teardown

devx_free_subscription() can remain queued after the last DevX event file
drops its module reference or an auxiliary driver detaches its devices.
mlx5_ib can then unload before the callback runs.

Registration error unwind has the same risk because driver registration
can attach existing devices before failing. Wait after all drivers have
stopped.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use‑after‑free potentially causing system instability or denial of service
Action: Update kernel
AI Analysis

Impact

The vulnerability lies in the RDMA mlx5 driver, where the devx_free_subscription() callback can remain queued after the last reference to the module is released or an auxiliary driver detaches its devices. When the mlx5_ib driver unloads before that callback runs, the callback executes on a no‑longer‑existent module, creating a use‑after‑free condition. This flaw enables a race condition that could lead to crashes, kernel panic, or other disruptive failures, impacting the availability of the affected system.

Affected Systems

All Linux kernel builds that contain the RDMA mlx5 driver are affected. The exact versions are not specified in the public data, so any kernel that ships the mlx5 module without an applied patch is at risk. Devices that rely on devx or aml_driver interfaces are potentially sensitive if the driver is unloaded while still in use.

Risk and Exploitability

The EPSS score is below 1%, indicating a very low likelihood of exploitation in the wild, and no alerts exist in the CISA KEV catalog. However, the flaw remains a severe race condition. Based on the description, it is inferred that an attacker with local or privileged access who can trigger module unloading or manipulate RDMA events could exploit the race to destabilize the system. Current best practice is to treat this as a high‑severity issue that warrants patching at the earliest opportunity.

Generated by OpenCVE AI on September 19, 2026 at 08:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel release that includes the RDMA mlx5 driver fix for the devx_free_subscription() RCU callback issue.
  • If an update cannot be applied immediately, avoid unloading RDMA drivers until all device references are released and ensure that no DevX events are being processed.
  • Configure system monitoring to alert on unexpected kernel crashes or RCU‑related warnings that may indicate the race condition has occurred.

Generated by OpenCVE AI on September 19, 2026 at 08:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Drain RCU callbacks during module teardown devx_free_subscription() can remain queued after the last DevX event file drops its module reference or an auxiliary driver detaches its devices. mlx5_ib can then unload before the callback runs. Registration error unwind has the same risk because driver registration can attach existing devices before failing. Wait after all drivers have stopped.
Title RDMA/mlx5: Drain RCU callbacks during module teardown
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:19.135Z

Reserved: 2026-09-17T16:02:15.085Z

Link: CVE-2026-93109

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:05.327

Modified: 2026-09-17T17:18:05.327

Link: CVE-2026-93109

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:15:14Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-416

    Use After Free