-

CVE-2026-80984

net/smc: do not dereference an unset send buffer on the SMC-D teardown path

In the Linux kernel, the following vulnerability has been resolved:

net/smc: do not dereference an unset send buffer on the SMC-D teardown path

smc_close_stream_wait() calls smc_tx_prepared_sends() from inside its
sk_wait_event() condition, and sk_wait_event() evaluates that condition
once with the socket lock released. smcd_buf_detach() clears
conn->sndbuf_desc from smc_conn_kill() under lock_sock(), so a link group
terminating while a socket waits there leaves the helper dereferencing
NULL, faulting out of close(). SIOCOUTQ reads the field by hand, and
smc_close_cancel_work() drops the lock across two cancel_*_sync() calls.

Sample the pointer once in the helper, report nothing prepared while it is
unset, and bound the ioctl the same way. The receive tasklet dereferences
the field directly in smc_cdc_msg_recv_action(), not through this helper;
1/2 is what keeps it from running that late.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 21f6f41e82e59740e26e06e77bdf58dc7f6f08dd
Version < ab26e12dd5d2f43d939fcf456933a816e81d2e51
Status affected
Version ae2be35cbed2c8385e890147ea321a3fcc3ca5fa
Version < e3fcff8d22a6c9540748846cd800443a643553a6
Status affected
Version ae2be35cbed2c8385e890147ea321a3fcc3ca5fa
Version < f950e1b1f0aad334f9a9ee552c4dd5b794ebdd45
Status affected
Version ae2be35cbed2c8385e890147ea321a3fcc3ca5fa
Version < f517cf02033801a28f98d86ca613a3533cf066b3
Status affected
Version ae2be35cbed2c8385e890147ea321a3fcc3ca5fa
Version < b395dd319cea422239cb45b998fb38d7e373af87
Status affected
Version 6.6.66
Version < 6.6.157
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.10
Status affected
Version 0
Version < 6.10
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.1
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/e3fcff8d22a6c9540748846cd800443a643553a6
https://git.kernel.org/stable/c/f950e1b1f0aad334f9a9ee552c4dd5b794ebdd45
https://git.kernel.org/stable/c/f517cf02033801a28f98d86ca613a3533cf066b3
https://git.kernel.org/stable/c/b395dd319cea422239cb45b998fb38d7e373af87
https://git.kernel.org/stable/c/ab26e12dd5d2f43d939fcf456933a816e81d2e51