Database/Kernel, userspace & hypervisor
Linux kernel SMC (struct smc_sock type confusion with inet_sock): Struct smc_sock does not embed struct inet_sock as
Impact
Struct smc_sock does not embed struct inet_sock as its first member but claims AF_INET/AF_INET6 in sk_family, so generic IPv4 socket code operates on it as if it were an inet_sock. syzbot's report shows cipso_v4_sock_setattr() freeing what it thinks is inet_opt but is actually smc_sock.clcsk_data_ready - a function pointer in the text segment. Type confusion that makes the kernel treat a function pointer as a heap pointer is a strong exploitation primitive, and it is reachable by any unprivileged process that can create an SMC socket.
Who can reach it
Local, unprivileged. Create an AF_SMC socket and drive it through generic IPv4 socket options (the reported path is CIPSO).
What to do
Kernel update correcting the socket type handling. Immediate mitigation is real here: block SMC socket creation for tenants (seccomp on the socket family, or keep the module unloaded), which removes the confusion entirely without a reboot.
References
Related entries
- Linux kernel (net/xfrm): The guard that forbids changing a collect_md xfrm interface never fired, so a changelink putsCVE-2025-38500 · Linux kernel (net/xfrm)High
- Linux kernel (drivers/iommu/intel): VT-d tore the device off the I/O page-fault queue before the hardware had stoppedCVE-2025-38594 · Linux kernel (drivers/iommu/intel)High
- Linux kernel (net/tls): KTLS assumes it owns the TCP receive queue. When another reader drains bytes first, the oldCVE-2025-38616 · Linux kernel (net/tls)High
- Linux kernel (net/xfrm): If the task is preempted onto another CPU during SA lookup, a hit in the per-CPU state cacheCVE-2025-38675 · Linux kernel (net/xfrm)High
- Linux kernel (drivers/gpu/drm/xe): Xe frees data that its exported dma-fences still point at - notably the timelineCVE-2025-38703 · Linux kernel (drivers/gpu/drm/xe)High
- Linux kernel (drivers/gpu/drm/xe): A tenant that submits a deliberately malformed array bind to the Xe VM_BIND ioctlCVE-2025-38731 · Linux kernel (drivers/gpu/drm/xe)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.