Database/Kernel, userspace & hypervisor
Linux kernel (net/smc): A link-down work item can be queued before the link group is freed but run after, so the worker
Impact
A link-down work item can be queued before the link group is freed but run after, so the worker operates on a freed link group - the published crash is list corruption (prev->next NULL) inside smc_link_down_work, i.e. a write through a freed pointer from a kworker. A peer that can flap an SMC-R link while connections are closing turns fabric noise into host memory corruption.
Who can reach it
Driven from the RDMA fabric: link-down work is scheduled from link/port events on the RoCE or IB device, and the race is against link-group teardown that tenants drive by closing SMC connections. No credentials are needed on either side - the fabric peer only has to cause a link event, and the local side only has to be running SMC-R (the smc module autoloads on an unprivileged socket(AF_SMC, ...)).
What to do
Boot a kernel carrying the fix commits (takes a link-group reference across the link-down work). Interim: blacklist the smc module on nodes not using SMC-R, and keep untrusted tenants off the RDMA fabric segment that can generate link events.
References
Related entries
- Linux kernel (net/smc): The SMC listen worker keeps touching the SMC socket after smc_listen_out() has handed it offCVE-2025-38734 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): An inbound SYN handled in softirq reads the smc_sock out of the listening TCP socket'sCVE-2026-23450 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): Link-group termination drops conns_lock after finding a connection but before taking a socketCVE-2026-74493 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): The IB port-up handler walks the global link-group list without holding its lock, so a fabricCVE-2023-54318 · Linux kernel (net/smc)High
- Linux kernel (net/smc): The CLC prefix-match check on the listen path dereferences the destination cache entry'sCVE-2025-40168 · Linux kernel (net/smc)High
- Linux kernel (net/smc): The CDC send-completion handler takes a lock inside an smc_sock that close() has already freedCVE-2021-46925 · Linux kernel (net/smc)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.