Database/Kernel, userspace & hypervisor
Linux kernel SMC-R/SMC-D (CLC proposal parsing, smcd_v2_ext_offset): The SMC server trusted an offset field taken
Impact
The SMC server trusted an offset field taken straight out of the connecting client's CLC proposal message. Exceeding the maximum turns it into an arbitrary displacement into the parsing buffer - out-of-bounds access chosen by an unauthenticated remote peer. SMC matters here because it is the transparent RDMA acceleration path: LD_PRELOAD smc_run in front of an ordinary TCP application and its sockets silently become RoCE, so this parser sits in front of workloads whose operators do not know they are running an RDMA protocol stack at all.
Who can reach it
Remote, unauthenticated. The CLC proposal is the first SMC message a client sends; parsing happens before anything is established.
What to do
Kernel update bounds-checking smcd_v2_ext_offset. Immediate mitigation: if SMC is not deliberately used, ensure the smc module is not loaded and that AF_SMC is not reachable - on many distro kernels it autoloads, so check rather than assume.
References
Related entries
- Linux kernel RTRS client (rtrs-clt init_conns connection-id bound): When connection setup fails partway through, theCVE-2024-47695 · Linux kernel RTRS client (rtrs-clt init_conns connection-id bound)Critical
- Linux kernel SMC-R/SMC-D (CLC proposal parsing, v2_ext_offset / eid_cnt / ism_gid_cnt): The same unvalidated-offsetCVE-2024-49568 · Linux kernel SMC-R/SMC-D (CLC proposal parsing, v2_ext_offset / eid_cnt / ism_gid_cnt)Critical
- Linux kernel mlx5_core kTLS TX offload: The kTLS TX path mixes get_page() and page_ref_inc() when acquiring referencesCVE-2024-53138 · Linux kernel mlx5_core kTLS TX offloadCritical
- Linux kernel (net/smc): The server-side listen worker frees a connection outside the socket lock, so smc_conn_free()CVE-2024-56640 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): A link-down work item can be queued before the link group is freed but run after, so the workerCVE-2024-56718 · Linux kernel (net/smc)Critical
- Linux kernel (net/tls): The synchronous decrypt path shared refcounting and completion state with the async path, so aCVE-2024-58240 · Linux kernel (net/tls)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.