-

CVE-2026-90108

net/smc: free stashed qentry before overwrite in REQ_ADD_LINK to ADD_LINK transition

In the Linux kernel, the following vulnerability has been resolved:

net/smc: free stashed qentry before overwrite in REQ_ADD_LINK to ADD_LINK transition

When smc_llc_event_handler() transitions the local LLC flow from
SMC_LLC_FLOW_REQ_ADD_LINK to SMC_LLC_FLOW_ADD_LINK on arrival of an ADD_LINK
request, it calls smc_llc_flow_qentry_set() unconditionally:

	if (lgr->llc_flow_lcl.type == SMC_LLC_FLOW_REQ_ADD_LINK) {
		lgr->llc_flow_lcl.type = SMC_LLC_FLOW_ADD_LINK;
		smc_llc_flow_qentry_set(&lgr->llc_flow_lcl, qentry);
		...
	}

A CONFIRM_LINK or ADD_LINK_CONT arriving while flow->type is
SMC_LLC_FLOW_REQ_ADD_LINK is stashed into flow->qentry via the
SMC_LLC_CONFIRM_LINK / SMC_LLC_ADD_LINK_CONT handler (which stores into
flow->qentry for any non-NONE flow type).  When the subsequent ADD_LINK
arrives, the REQ_ADD_LINK branch overwrites flow->qentry with the new pointer
without first freeing the stashed allocation, leaking one kmalloc object.

The stashed entry has no consumer: smc_llc_wait() is only called from
llc_add_link_work, which is not yet scheduled while the flow type remains
REQ_ADD_LINK.  No waiter is sleeping on llc_msg_waiter at this point.
It is safe to unconditionally free any stashed qentry before
the overwrite.

Call smc_llc_flow_qentry_del() before smc_llc_flow_qentry_set() in the
REQ_ADD_LINK branch.  smc_llc_flow_qentry_del() already checks flow->qentry
before freeing, so the normal path where no entry is stashed is a no-op.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version b4ba4652b3f8b7c9bbb5786f8acf4724bdab2196
Version < 7dd55348c0d9399a9448847819e9f3904ae507ad
Status affected
Version b4ba4652b3f8b7c9bbb5786f8acf4724bdab2196
Version < 056395acb7041b3a1f2baa08d89a1938a8b8776a
Status affected
Version b4ba4652b3f8b7c9bbb5786f8acf4724bdab2196
Version < b08aacfb226a840628151643b6a34eecf545d311
Status affected
Version b4ba4652b3f8b7c9bbb5786f8acf4724bdab2196
Version < 0fb9a513766071ea9d5f3bf988e39241b8e9ee3b
Status affected
Version b4ba4652b3f8b7c9bbb5786f8acf4724bdab2196
Version < e25a602c45c76a7130878db72bcf6f76df04bf85
Status affected
Version b4ba4652b3f8b7c9bbb5786f8acf4724bdab2196
Version < 036322025d6e440cb75fc6fecbba9a16b271a2ae
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.16
Status affected
Version 0
Version < 5.16
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.109
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/7dd55348c0d9399a9448847819e9f3904ae507ad
https://git.kernel.org/stable/c/056395acb7041b3a1f2baa08d89a1938a8b8776a
https://git.kernel.org/stable/c/b08aacfb226a840628151643b6a34eecf545d311
https://git.kernel.org/stable/c/0fb9a513766071ea9d5f3bf988e39241b8e9ee3b
https://git.kernel.org/stable/c/e25a602c45c76a7130878db72bcf6f76df04bf85
https://git.kernel.org/stable/c/036322025d6e440cb75fc6fecbba9a16b271a2ae