CVE-2026-93110
RDMA/core: Wait for RCU callbacks before unloading ib_core
Description
In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Wait for RCU callbacks before unloading ib_core put_gid_ndev() is queued with call_rcu() and implemented in ib_core. Stopping the workqueues does not drain callbacks already queued, so RCU could invoke it after the module code has been unloaded. synchronize_rcu() does not wait for callbacks. Wait for them after all producers have stopped.
INFO
Published Date :
Sept. 17, 2026, 5:18 p.m.
Last Modified :
Sept. 17, 2026, 5:18 p.m.
Remotely Exploit :
No
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Solution
- Update the Linux kernel to the resolved version.
- Ensure RCU callbacks complete before module unload.
- Stop RCU callback producers before unloading modules.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-93110.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-93110 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-93110
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-93110 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-93110 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Sep. 17, 2026
Action Type Old Value New Value Added Description In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Wait for RCU callbacks before unloading ib_core put_gid_ndev() is queued with call_rcu() and implemented in ib_core. Stopping the workqueues does not drain callbacks already queued, so RCU could invoke it after the module code has been unloaded. synchronize_rcu() does not wait for callbacks. Wait for them after all producers have stopped. Added Affected New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/93xxx/CVE-2026-93110.json">CVE-2026-93110</a> Added Reference https://git.kernel.org/stable/c/0d5817fa4819abdc445fa77b5be4f0d49334a864 Added Reference https://git.kernel.org/stable/c/1646e123e56c3ad679fbfb571e8eef6386efb729 Added Reference https://git.kernel.org/stable/c/48b72fa0d209a92fb51b834a6080171cfa207b2c Added Reference https://git.kernel.org/stable/c/7853af5f15738dc00aebaa1fc9f1f0df40f6f603 Added Reference https://git.kernel.org/stable/c/7d75592114d1664623c8cf191a12b38052c04483 Added Reference https://git.kernel.org/stable/c/82dfd1df456227279b1c8c648983a530f2612098 Added Reference https://git.kernel.org/stable/c/8e4f1677c09d75d738099f42afcf65d8587b664a Added Reference https://git.kernel.org/stable/c/9d998297fdaf47492f6679287f6552879d1a7e3a