Database/Kernel, userspace & hypervisor
Linux kernel (net/smc): An unprivileged tenant that opens an AF_SMC socket, registers it with epoll, and lets the
Impact
An unprivileged tenant that opens an AF_SMC socket, registers it with epoll, and lets the connection fall back to plain TCP leaves poisoned waitqueue entries behind; the TCP receive path then walks a corrupted list from softirq and takes a general protection fault. Any tenant can panic a shared node with a few dozen lines of ordinary socket code.
Who can reach it
Local, fully unprivileged, and on the common path: SMC falls back to TCP whenever the peer does not speak SMC, which is the default outcome for almost all traffic. socket(AF_SMC, ...) autoloads the smc module via the net-pf-43 alias with no capability check, so a plain tenant container - no /dev/infiniband, no RDMA device, no privileges - reaches it. The fault lands in NAPI/softirq context, so it takes the whole node down, not just the calling task.
What to do
Update to 5.15.22 or later on the 5.15 branch, or any kernel carrying the fix commits. Interim: blacklist the smc module (install smc /bin/false) or deny socket family 43 in the tenant seccomp profile - there is no in-kernel toggle for this path.
References
Related entries
- Linux kernel (net/smc): Closing an SMC socket can leave the internal TCP kernel socket with its timers still armed andCVE-2023-53781 · Linux kernel (net/smc)High
- Linux kernel (net/smc): SMC-D loopback registers DMBs (the direct memory buffers a peer reads and writes) out ofCVE-2025-40012 · Linux kernel (net/smc)High
- Linux kernel (net/smc): Connect() on an SMC socket takes the destination device pointer out of the dst cache without aCVE-2025-40064 · Linux kernel (net/smc)High
- Linux kernel (net/smc): Tee(2) duplicates an SMC splice pipe buffer without duplicating the private state hanging offCVE-2026-31507 · Linux kernel (net/smc)High
- Linux kernel (net/smc): The SMC socket hashtables are re-initialised at the end of module init, after the protocol andCVE-2026-64005 · Linux kernel (net/smc)High
- Linux kernel (net/smc): On hosts using soft-RoCE, the IB device has no DMA device, and the SMC buffer-mapping pathCVE-2025-39857 · Linux kernel (net/smc)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.