Database/Kernel, userspace & hypervisor
Linux kernel (net/smc): On the server side of the SMC-R LLC handshake, adding a second link to a link group runs
Impact
On the server side of the SMC-R LLC handshake, adding a second link to a link group runs without the link-configuration mutex, so a remote client can race link addition against buffer registration and drive the host into ib_alloc_mr with a torn link structure. The published result is a kernel page fault during memory-region allocation - a remote, pre-authentication panic of the node from an unauthenticated connecting peer.
Who can reach it
Pre-authentication and driven entirely by the connecting peer: the LLC ADD LINK exchange happens during SMC-R connection setup, before any application-level authentication. Any host on the RDMA fabric that can complete a TCP connection to an SMC-enabled listener and negotiate SMC-R can drive it. Requires SMC-R to be in use (an RoCE/IB device plus a listener whose sockets fall into SMC), which is the normal case once the smc module is loaded.
What to do
Boot a kernel carrying the fix commits (serialises smc_llc_srv_add_link under llc_conf_mutex). Interim: stop terminating tenant or east-west traffic on SMC-R listeners, blacklist the smc module on nodes not using it, and restrict which fabric peers can open TCP connections to SMC-capable services.
References
Related entries
- Linux kernel (net/smc): The server-side listen worker frees a connection outside the socket lock, so smc_conn_free()CVE-2024-56640 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): A link-down work item can be queued before the link group is freed but run after, so the workerCVE-2024-56718 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): The SMC listen worker keeps touching the SMC socket after smc_listen_out() has handed it offCVE-2025-38734 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): An inbound SYN handled in softirq reads the smc_sock out of the listening TCP socket'sCVE-2026-23450 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): Link-group termination drops conns_lock after finding a connection but before taking a socketCVE-2026-74493 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): The IB port-up handler walks the global link-group list without holding its lock, so a fabricCVE-2023-54318 · Linux kernel (net/smc)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.