net/smc: fix socket use-after-free during link group termination
Summary
| CVE | CVE-2026-74493 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-15 13:17:54 UTC |
| Updated | 2026-08-15 13:17:54 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
net/smc: fix socket use-after-free during link group termination
__smc_lgr_terminate() drops conns_lock after finding a connection in
lgr->conns_all, but before taking a reference on its socket. The connection
is embedded in the socket, and its registration reference protects it only
while the connection remains in the tree.
A concurrent close can unregister the connection and drop that reference,
freeing the socket before the termination worker reaches sock_hold().
The race is reachable when close overlaps link group termination.
Local stress testing reproduced the use-after-free and KASAN reported:
BUG: KASAN: slab-use-after-free in __smc_lgr_terminate.part.0 [smc]
Write of size 4 by task kworker/3:3
Workqueue: events smc_lgr_terminate_work [smc]
__smc_lgr_terminate.part.0 [smc]
The socket was allocated by smc_create(), freed through
slab_free_after_rcu_debug(), and was followed by:
refcount_t: addition on 0; use-after-free.
__smc_lgr_terminate.part.0 [smc]
Take the socket reference while conns_lock still protects the tree entry.
The unregister path then cannot drop the last reference until termination
has finished using the socket. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 69318b5215f2dc32c345a3d65b98b4b1bf29c007 5a42f162b857019a4c10ff687dc3bcdf51831865 git |
Not specified |
| CNA |
Linux |
Linux |
affected 69318b5215f2dc32c345a3d65b98b4b1bf29c007 281c103a8eaed59001ce952f231df1b07674215a git |
Not specified |
| CNA |
Linux |
Linux |
affected 69318b5215f2dc32c345a3d65b98b4b1bf29c007 f807a63d0d95680c34f677700da9148a07d7c78f git |
Not specified |
| CNA |
Linux |
Linux |
affected 69318b5215f2dc32c345a3d65b98b4b1bf29c007 f0541a775d04c88e90ba448e35ce0d743512822a git |
Not specified |
| CNA |
Linux |
Linux |
affected 69318b5215f2dc32c345a3d65b98b4b1bf29c007 f621d6ebeebb6374342571e4ddf45fdbc420f6cd git |
Not specified |
| CNA |
Linux |
Linux |
affected 5.5 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.5 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.151 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.103 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.44 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.8 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2-rc6 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/281c103a8eaed59001ce952f231df1b07674215a |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/5a42f162b857019a4c10ff687dc3bcdf51831865 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/f807a63d0d95680c34f677700da9148a07d7c78f |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/f0541a775d04c88e90ba448e35ce0d743512822a |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/f621d6ebeebb6374342571e4ddf45fdbc420f6cd |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.