Database/Kernel, userspace & hypervisor
Linux kernel SMC-R/SMC-D (CLC proposal parsing, iparea_offset / ipv6_prefixes_cnt): Third instance of the same class in
Impact
Third instance of the same class in the same handshake parser - the IP-area offset and the IPv6 prefix count are taken from the remote client without bounds checks, giving an unauthenticated peer an out-of-bounds read on the server. That three separate patches were needed for one message format is the real finding: the SMC CLC parser was written assuming a cooperative peer, and an operator should treat the whole surface as untrusted rather than patching field by field.
Who can reach it
Remote, unauthenticated, first message of the SMC handshake.
What to do
Kernel update validating iparea_offset and ipv6_prefixes_cnt. Given the pattern, the durable control is not exposing AF_SMC on tenant-reachable interfaces at all unless SMC acceleration is a deliberate design choice.
References
Related entries
- Go x/crypto ssh/agent: destination restrictions silently dropped when adding keys to a remote agentCVE-2026-39832 · golang.org/x/crypto/ssh/agent (constraint extension serialization)Critical
- Linux kernel - NVMe-oF target DH-HMAC-CHAP authentication, drivers/nvme/target/fabrics-cmd-auth.c: Nvmet_auth_reply()CVE-2026-64319 · Linux kernel - NVMe-oF target DH-HMAC-CHAP authentication, drivers/nvme/target/fabrics-cmd-auth.cCritical
- Linux kernel - NVMe-oF target discovery controller, drivers/nvme/target/discovery.c: The discovery controller validatedCVE-2026-64320 · Linux kernel - NVMe-oF target discovery controller, drivers/nvme/target/discovery.cCritical
- perf tools: out-of-bounds heap read parsing a crafted perf.data CPU indexCVE-2026-80670 · Linux kernel perf tools (machine__resolve() CPU index from perf.data samples)Critical
- Linux NFSD: NFSv2 SETATTR reaches notify_change without a mount write referenceCVE-2026-89697 · Linux kernel NFSD (nfsd_proc_setattr, NFSv2 BOTH_TIME_SET path)Critical
- Linux NFSD: TOCTOU lets a SETATTR truncate an append-only fileCVE-2026-89713 · Linux kernel NFSD (nfsd_setattr ATTR_SIZE truncate permission check)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.