Database/Kernel, userspace & hypervisor
Linux kernel SMC-R (fallback path, DECLINE message leaking into the application stream): Silent data corruption, which
Impact
Silent data corruption, which is worse than a crash because nothing alerts. When SMC falls back to TCP, an in-flight SMC DECLINE control message could be delivered into the application's data stream - the reporters found Redis receiving raw SMC protocol bytes (0xE2 0xD4 0xC3 0xD9 ...) as if they were payload. On a training cluster the equivalent is protocol bytes landing inside a checkpoint shard or a gradient transfer: the job does not fail, it produces wrong results, and you find out weeks later if at all.
Who can reach it
Remote/network. A peer that triggers SMC fallback at the wrong moment - or ordinary network conditions that cause fallback - injects control bytes into the data stream. No authentication involved.
What to do
Kernel update preventing the decline message from reaching the socket's data path. Until patched, treat any SMC-accelerated flow as unsuitable for data whose integrity you cannot verify end to end, and add application-level checksums to checkpoint and dataset transfers - which is good practice regardless of this bug.
References
Related entries
- QEMU (virtio): DMA reentrancy leads to double free across virtio devices - guest-to-host code execution in QEMUCVE-2024-3446 · QEMU (virtio)High
- Linux kernel (net/tls): A non-DATA record already copied out of the pending list could be merged with a second recordCVE-2024-58239 · Linux kernel (net/tls)High
- Intel ice driver (Ethernet 800 Series, Linux kernel mode): A missing check for an exceptional condition in theCVE-2025-20093 · Intel ice driver (Ethernet 800 Series, Linux kernel mode)High
- VMware ESXi: Arbitrary kernel write from the VMX process - sandbox escape completing the zero-day chainCVE-2025-22225 · VMware ESXiHigh
- OpenStack Nova: crafted QCOW header on a Flat-backend disk lets a tenant destroy host data on resizeCVE-2026-24708 · OpenStack Nova (Flat image backend, qemu-img resize)High
- Linux kernel (drivers/iommu/intel): A device that does not support ATS never gets inserted into the VT-d deviceCVE-2026-74355 · Linux kernel (drivers/iommu/intel)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.