Junglewise Threat Intelligence

CVE-2026-93109: Linux kernel RDMA/mlx5 use-after-free during module teardown

CVE-2026-93109 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's RDMA/mlx5 driver (which handles remote direct memory access networking for Mellanox adapters) has a timing issue during shutdown where callback functions can execute after the driver module has unloaded, potentially causing kernel crashes or memory corruption. This affects systems using Mellanox RDMA networking hardware when the driver is unloaded or when auxiliary drivers detach their devices.

Technical details

The vulnerability is a use-after-free condition in the RDMA/mlx5 driver's module teardown path. The `devx_free_subscription()` callback can remain queued in the RCU callback queue after the module reference count drops to zero or auxiliary drivers detach. The driver can unload before the queued callback executes, causing it to reference freed memory. The same race condition exists in the driver registration error unwind path. The fix adds `rcu_barrier()` calls to synchronously drain all pending RCU callbacks before proceeding with cleanup, ensuring callbacks complete before module unload. This is a defensive patch addressing a timing race, not an actively exploited vulnerability.

Affected products

  • Linux Linux kernel RDMA/mlx5 driver in kernel 5.7 and later

Timeline

  • 2026-09-17: disclosed
  • 2026-07-12: patched

References

Related threats