Database/Kernel, userspace & hypervisor
Linux kernel (net/smc): The CDC send-completion handler takes a lock inside an smc_sock that close() has already freed
Impact
The CDC send-completion handler takes a lock inside an smc_sock that close() has already freed, so a tenant that closes an SMC connection while a control-data-connection message is still in flight gets a use-after-free write in tasklet context. The published crash is a fatal page fault in _raw_spin_lock from the RDMA completion path - a hard node panic, with the freed-object write usable as a corruption primitive.
Who can reach it
Local and unprivileged: open an SMC-R connection, send, then close while a CDC message is outstanding - the race is between smc_release() and the WR completion tasklet, so it is a timing loop any tenant can run. Requires SMC-R actually negotiating over an RDMA device on the node; the smc module itself autoloads from an unprivileged socket(AF_SMC, ...) call.
What to do
Boot a kernel carrying the fix commits (adds a refcount so CDC completions cannot outlive the socket). Interim: blacklist smc, or deny socket family 43 to tenants, on nodes where SMC-R is not deliberately in use.
References
Related entries
- Linux kernel (net/smc): An unprivileged tenant that opens an AF_SMC socket, registers it with epoll, and lets theCVE-2022-48721 · Linux kernel (net/smc)High
- Linux kernel (net/smc): Closing an SMC socket can leave the internal TCP kernel socket with its timers still armed andCVE-2023-53781 · Linux kernel (net/smc)High
- Linux kernel (net/smc): SMC-D loopback registers DMBs (the direct memory buffers a peer reads and writes) out ofCVE-2025-40012 · Linux kernel (net/smc)High
- Linux kernel (net/smc): Connect() on an SMC socket takes the destination device pointer out of the dst cache without aCVE-2025-40064 · Linux kernel (net/smc)High
- Linux kernel (net/smc): Tee(2) duplicates an SMC splice pipe buffer without duplicating the private state hanging offCVE-2026-31507 · Linux kernel (net/smc)High
- Linux kernel (net/smc): The SMC socket hashtables are re-initialised at the end of module init, after the protocol andCVE-2026-64005 · Linux kernel (net/smc)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.