Database/Kernel, userspace & hypervisor
Linux kernel (net/smc): The early link-group cleanup path deletes the list head instead of the link group, so the group
Impact
The early link-group cleanup path deletes the list head instead of the link group, so the group stays on the global list and is then memset while still linked. Subsequent list operations write through a poisoned pointer - the published failure is a list-corruption BUG in the link-down worker, and the same defect gives an attacker who can force early link-group teardown a controlled-ish write into freed memory.
Who can reach it
Driven from the fabric: the cleanup path runs when link-group setup aborts early, which a peer can force by failing or aborting the CLC handshake, and the crash was observed from the smc_link_down worker (a fabric link event). Local tenants reach the same path through repeated AF_SMC connect attempts; socket(AF_SMC, ...) is unprivileged and autoloads the module.
What to do
Boot a kernel carrying the fix commits. Interim: blacklist the smc module or block socket family 43 for tenants on nodes that do not intentionally run SMC-R.
References
Related entries
- Linux kernel (net/smc): When an SMC-R link is torn down, the kernel moves the QP to Error state and then destroys theCVE-2022-48673 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): When an incoming connection tries SMC-Rv2 and device setup fails, the listener does not resetCVE-2023-53382 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): On the server side of the SMC-R LLC handshake, adding a second link to a link group runsCVE-2023-54237 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): The server-side listen worker frees a connection outside the socket lock, so smc_conn_free()CVE-2024-56640 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): A link-down work item can be queued before the link group is freed but run after, so the workerCVE-2024-56718 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): The SMC listen worker keeps touching the SMC socket after smc_listen_out() has handed it offCVE-2025-38734 · Linux kernel (net/smc)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.