-
CVE-2026-80983
- EPSS 0.17%
- Veröffentlicht 11.09.2026 19:42:42
- Zuletzt bearbeitet 14.09.2026 13:18:53
- Erkennungen
net/smc: fix socket refcount leak in smc_switch_conns()
In the Linux kernel, the following vulnerability has been resolved:
net/smc: fix socket refcount leak in smc_switch_conns()
smc_switch_conns() takes a reference on the SMC socket before dropping
lgr->conns_lock, so the connection stays alive while the CDC slot is
fetched:
sock_hold(&smc->sk);
read_unlock_bh(&lgr->conns_lock);
/* pre-fetch buffer outside of send_lock, might sleep */
rc = smc_cdc_get_free_slot(conn, to_lnk, &wr_buf, NULL, &pend);
if (rc)
goto err_out;
The err_out label only drops the wr_tx link reference, so this early exit
returns without the matching sock_put(). The second error exit is not
affected, because sock_put() has already run by then.
A leaked sk_refcnt means the smc_sock is never destroyed. Its send and
receive buffers stay allocated, and for a user socket the reference held
on the network namespace is never released, so the netns can no longer be
torn down.
smc_cdc_get_free_slot() fails when the target link goes down or when the
connection has been killed while the switch is in progress. Both are
reachable during the link failover this function implements, so the leak
is triggered by the same hardware events that make smc_switch_conns() run
in the first place.
Restructure so there is a single sock_put() covering both outcomes,
instead of adding a second one to the error path.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
95f7f3e7dc6bd2e735cb5de11734ea2222b1e05a
Version <
a3378466704e0bbe93aef9769552dca7673a7eb6
Status
affected
Version
95f7f3e7dc6bd2e735cb5de11734ea2222b1e05a
Version <
e20227019d9da73f8fdf16f0951c2e188c84933f
Status
affected
Version
95f7f3e7dc6bd2e735cb5de11734ea2222b1e05a
Version <
09d7a9e162ee1a269878c126aee3d7eff43e4130
Status
affected
Version
95f7f3e7dc6bd2e735cb5de11734ea2222b1e05a
Version <
84dea0585f6b538ae895a8b1d025f4897737f3b1
Status
affected
Version
95f7f3e7dc6bd2e735cb5de11734ea2222b1e05a
Version <
d89dc1bd8845c669a700eee58c64ebd3cc1b6d2d
Status
affected
Version
95f7f3e7dc6bd2e735cb5de11734ea2222b1e05a
Version <
d9a879ac25958bdaecb669ce70e58f8e2ff170de
Status
affected
Version
95f7f3e7dc6bd2e735cb5de11734ea2222b1e05a
Version <
719296c4aa8213d4ac8002e77d5956d436bc98d0
Status
affected
Version
99f19566b1c4d3dc4d934ee2ef43faadebb56d70
Status
affected
Version
0d9ddf515cde793841f738490037560fd6559c63
Status
affected
Version
5.10.90
Version <
5.11
Status
affected
Version
5.14.14
Version <
5.15
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.15
Status
affected
Version
0
Version <
5.15
Status
unaffected
Version <=
5.15.*
Version
5.15.221
Status
unaffected
Version <=
6.1.*
Version
6.1.188
Status
unaffected
Version <=
6.6.*
Version
6.6.157
Status
unaffected
Version <=
6.12.*
Version
6.12.109
Status
unaffected
Version <=
6.18.*
Version
6.18.50
Status
unaffected
Version <=
7.2.*
Version
7.2.4
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.063 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/84dea0585f6b538ae895a8b1d025f4897737f3b1
https://git.kernel.org/stable/c/d89dc1bd8845c669a700eee58c64ebd3cc1b6d2d
https://git.kernel.org/stable/c/d9a879ac25958bdaecb669ce70e58f8e2ff170de
https://git.kernel.org/stable/c/719296c4aa8213d4ac8002e77d5956d436bc98d0
https://git.kernel.org/stable/c/09d7a9e162ee1a269878c126aee3d7eff43e4130
https://git.kernel.org/stable/c/a3378466704e0bbe93aef9769552dca7673a7eb6
https://git.kernel.org/stable/c/e20227019d9da73f8fdf16f0951c2e188c84933f