Database/Kernel, userspace & hypervisor
Linux kernel (net/smc): When an incoming connection tries SMC-Rv2 and device setup fails, the listener does not reset
Impact
When an incoming connection tries SMC-Rv2 and device setup fails, the listener does not reset the connection and goes on to build the CLC ACCEPT/CONFIRM message from half-initialised state, dereferencing a NULL link pointer inside the handshake worker. A remote client can crash the server node during connection setup, before any authentication, and the reproducer is nothing more exotic than nginx plus a load generator over SMC-R.
Who can reach it
Remote and pre-authentication: the fault is in smc_listen_work / smc_clc_send_confirm_accept, i.e. the server side of the CLC handshake, reachable by any fabric peer that connects to an SMC-enabled listening service. Requires SMC-Rv2 negotiation over RoCE (the report used two Mellanox ConnectX-4 adapters); the crash is in a kworker, so it takes the node with it.
What to do
Boot a kernel carrying the fix commits (resets the connection when SMC-Rv2 setup fails). Interim: disable SMC-Rv2 negotiation, keep tenant-reachable services off SMC listeners, and blacklist the smc module on nodes that do not need it.
References
Related entries
- Linux kernel (net/smc): On the server side of the SMC-R LLC handshake, adding a second link to a link group runsCVE-2023-54237 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): The server-side listen worker frees a connection outside the socket lock, so smc_conn_free()CVE-2024-56640 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): A link-down work item can be queued before the link group is freed but run after, so the workerCVE-2024-56718 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): The SMC listen worker keeps touching the SMC socket after smc_listen_out() has handed it offCVE-2025-38734 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): An inbound SYN handled in softirq reads the smc_sock out of the listening TCP socket'sCVE-2026-23450 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): Link-group termination drops conns_lock after finding a connection but before taking a socketCVE-2026-74493 · Linux kernel (net/smc)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.