Database/Kernel, userspace & hypervisor
Linux kernel (net/smc): The server-side listen worker frees a connection outside the socket lock, so smc_conn_free()
Impact
The server-side listen worker frees a connection outside the socket lock, so smc_conn_free() and the link/link-group refcount drops can run twice for the same connection. The refcount saturates (addition-on-zero / underflow warnings) and the link group and link are released while still in use - a remote-driven use-after-free of the RDMA link state that a connecting peer can provoke by failing device negotiation at the right moment.
Who can reach it
Remote, pre-authentication: the double free happens in smc_listen_work / smc_listen_find_device, the server side of SMC connection setup, so any fabric peer able to reach an SMC-capable listener and abort or fail device negotiation drives it. Requires SMC in use on the listening node; the module autoloads from an unprivileged socket(AF_SMC, ...) call.
What to do
Boot a kernel carrying the fix commits (takes the socket lock across the listen-path connection teardown). Interim: keep tenant-reachable services off SMC listeners and blacklist the smc module on nodes not using SMC-R.
References
Related entries
- Linux kernel (net/smc): A link-down work item can be queued before the link group is freed but run after, so the workerCVE-2024-56718 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): The SMC listen worker keeps touching the SMC socket after smc_listen_out() has handed it offCVE-2025-38734 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): An inbound SYN handled in softirq reads the smc_sock out of the listening TCP socket'sCVE-2026-23450 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): Link-group termination drops conns_lock after finding a connection but before taking a socketCVE-2026-74493 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): The IB port-up handler walks the global link-group list without holding its lock, so a fabricCVE-2023-54318 · Linux kernel (net/smc)High
- Linux kernel (net/smc): The CLC prefix-match check on the listen path dereferences the destination cache entry'sCVE-2025-40168 · Linux kernel (net/smc)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.