net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket
Summary
| CVE | CVE-2026-64541 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-27 21:17:06 UTC |
| Updated | 2026-07-27 21:17:06 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket
smc_cdc_rx_handler() looks up the connection by token under the link
group's conns_lock, drops the lock, and then dereferences conn and the
smc_sock derived from it, ending in sock_hold(&smc->sk) inside
smc_cdc_msg_recv(). No reference is held across the lock release.
The only reference pinning the socket while the connection is
discoverable in the link group is taken in smc_lgr_register_conn()
(sock_hold) and dropped in __smc_lgr_unregister_conn() (sock_put), both
under conns_lock. Once the handler drops conns_lock, a concurrent
close() -> smc_release() -> smc_conn_free() -> smc_lgr_unregister_conn()
can drop that reference and free the smc_sock, so the handler's later
sock_hold() runs on freed memory:
WARNING: lib/refcount.c:25 at refcount_warn_saturate
Workqueue: rxe_wq do_work
refcount_warn_saturate (lib/refcount.c:25)
smc_cdc_msg_recv (net/smc/smc_cdc.c:430)
smc_cdc_rx_handler (net/smc/smc_cdc.c:502)
smc_wr_rx_tasklet_fn (net/smc/smc_wr.c:445)
tasklet_action_common (kernel/softirq.c:938)
handle_softirqs (kernel/softirq.c:622)
Kernel panic - not syncing: panic_on_warn set
Only SMC-R is affected. The SMC-D receive tasklet is stopped by
tasklet_kill(&conn->rx_tsklet) in smc_conn_free() before the connection
is unregistered, so it cannot run concurrently with the free.
Take the socket reference while still holding conns_lock, so the
registration reference can no longer be the last one, and drop it once
the handler is done. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected d7b0e37c1ac152905b18a5b9506179091a35b0b6 8de4f665d0febfb92803dece377791a563fc7041 git |
Not specified |
| CNA |
Linux |
Linux |
affected d7b0e37c1ac152905b18a5b9506179091a35b0b6 8145b432136285e01091815b48ceb2dae261f262 git |
Not specified |
| CNA |
Linux |
Linux |
affected d7b0e37c1ac152905b18a5b9506179091a35b0b6 1951bffbc6493ec34cff3956b29d4bc6606904a6 git |
Not specified |
| CNA |
Linux |
Linux |
affected d7b0e37c1ac152905b18a5b9506179091a35b0b6 647b19e5cc145a2f1f685ae8ff3805a17356888c git |
Not specified |
| CNA |
Linux |
Linux |
affected d7b0e37c1ac152905b18a5b9506179091a35b0b6 472e9d7c0d5b03be3ff91ff941f57da822b031bc git |
Not specified |
| CNA |
Linux |
Linux |
affected d7b0e37c1ac152905b18a5b9506179091a35b0b6 3bfb96d9bc6a7ed0b99c7db329cc2e22a28d84bb git |
Not specified |
| CNA |
Linux |
Linux |
affected d7b0e37c1ac152905b18a5b9506179091a35b0b6 ce5aa8084329351086894aa34d77e40301d5bd3d git |
Not specified |
| CNA |
Linux |
Linux |
affected d7b0e37c1ac152905b18a5b9506179091a35b0b6 9d160b35cc34a2ba8229d07651468a7848325135 git |
Not specified |
| CNA |
Linux |
Linux |
affected 4.18 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 4.18 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.10.261 5.10.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.15.212 5.15.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.1.178 6.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.145 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.97 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.40 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.5 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2-rc3 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/472e9d7c0d5b03be3ff91ff941f57da822b031bc |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/9d160b35cc34a2ba8229d07651468a7848325135 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/647b19e5cc145a2f1f685ae8ff3805a17356888c |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/3bfb96d9bc6a7ed0b99c7db329cc2e22a28d84bb |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/1951bffbc6493ec34cff3956b29d4bc6606904a6 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/8145b432136285e01091815b48ceb2dae261f262 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/ce5aa8084329351086894aa34d77e40301d5bd3d |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/8de4f665d0febfb92803dece377791a563fc7041 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.