Description
In the Linux kernel, the following vulnerability has been resolved:

RDMA/core: Wait for RCU callbacks before unloading ib_core

put_gid_ndev() is queued with call_rcu() and implemented in ib_core.
Stopping the workqueues does not drain callbacks already queued, so RCU
could invoke it after the module code has been unloaded.

synchronize_rcu() does not wait for callbacks. Wait for them after all
producers have stopped.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

In the Linux kernel, a bug in the RDMA core stack allows a pending RCU callback to be invoked after the ib_core module has already been unloaded. The callback is queued with call_rcu() from put_gid_ndev() and the module unload sequence does not wait for these callbacks to finish. If the callback executes after the module’s code has been removed, it results in a use‑after‑free that can crash the kernel, leading to a denial of service. This issue is closely related to CWE‑416: Use After Free.

Affected Systems

The vulnerability affects any Linux kernel that includes the ib_core module, typically found in kernel releases that support InfiniBand RDMA networking. The specific affected versions are not enumerated in the public data, so any kernel configured with ib_core remains at risk until updated.

Risk and Exploitability

The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of widespread exploitation at present. However, the severity is high if an attacker can unload the ib_core module or force the module to be unloaded in a running system, potentially causing a kernel crash. The primary attack vector is an action that unloads or reloads the module; acquiring module unload privileges is required to realize the exploit.

Generated by OpenCVE AI on September 19, 2026 at 07:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that contains the ib_core unload wait fix.
  • If an immediate kernel update is not viable, avoid unloading the ib_core module on production systems; maintain the module for the lifetime of the RDMA subsystem.
  • For custom kernel builds, apply the upstream patch that implements the RCU wait before unload as referenced in the kernel commit logs and verify the patch in a test environment before deployment.

Generated by OpenCVE AI on September 19, 2026 at 07:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Wait for RCU callbacks before unloading ib_core put_gid_ndev() is queued with call_rcu() and implemented in ib_core. Stopping the workqueues does not drain callbacks already queued, so RCU could invoke it after the module code has been unloaded. synchronize_rcu() does not wait for callbacks. Wait for them after all producers have stopped.
Title RDMA/core: Wait for RCU callbacks before unloading ib_core
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:19.805Z

Reserved: 2026-09-17T16:02:15.085Z

Link: CVE-2026-93110

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:05.450

Modified: 2026-09-17T17:18:05.450

Link: CVE-2026-93110

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:45:11Z

Weaknesses