Database/Kernel, userspace & hypervisor
Linux kernel SMC (CLC message drain loop, unchecked sock_recvmsg return): The length field in the CLC header is
Impact
The length field in the CLC header is attacker-supplied, and when it exceeds the local buffer the code drains the remainder without checking the receive return value - so a peer that declares a huge length and then stops sending puts the kernel in an unbounded drain loop. One connection from an unauthenticated peer wedges a kernel thread; a handful wedge the node.
Who can reach it
Remote, unauthenticated. Send a CLC header with an oversized length and withhold the rest.
What to do
Kernel update checking the sock_recvmsg return during the drain. Keep AF_SMC unreachable from tenant networks where SMC is not in use.
References
Related entries
- QEMU (NBD server): Improper synchronisation during socket closure - DoS of the QEMU NBD serverCVE-2024-7409 · QEMU (NBD server)High
- QEMU: use-after-free in the VNC WebSocket handshake crashes the VM process before client authenticationCVE-2025-11234 · QEMU QIOChannelWebsock (VNC WebSocket handshake)High
- Linux kernel (net/tls): If a page allocation fails while the TLS strparser is copying a partial record, the receiveCVE-2025-38018 · Linux kernel (net/tls)High
- Linux kernel (drivers/nvme/target): A connecting client that abandons the TCP connection at the right moment duringCVE-2025-38035 · Linux kernel (drivers/nvme/target)High
- Linux kernel (net/xfrm): Several error paths in the ESP-in-TCP receive code return without freeing the skb, soCVE-2025-38057 · Linux kernel (net/xfrm)High
- Linux kernel (drivers/nvme/target): Every command a client sends to the target carrying metadata (protectionCVE-2025-38405 · Linux kernel (drivers/nvme/target)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.