Database/Kernel, userspace & hypervisor
Linux kernel (net/smc): SMC-D loopback registers DMBs (the direct memory buffers a peer reads and writes) out of
Impact
SMC-D loopback registers DMBs (the direct memory buffers a peer reads and writes) out of kmalloc memory, which is not page-backed, so the receive path cannot take a page reference before handing the buffer to a pipe. splice() from an SMC-D socket therefore runs against a buffer that can be freed under it - a use-after-free on the remote-memory-buffer path reachable by an ordinary tenant.
Who can reach it
Local and unprivileged, conditional on the SMC-D loopback ISM device being available (the smc_loopback module - present on s390 and on x86 kernels that ship loopback-ism). A tenant opens an AF_SMC socket that negotiates SMC-D over loopback and splices from it; no capability, no device node, and no RDMA hardware is needed, and socket(AF_SMC, ...) autoloads the family itself.
What to do
Boot a kernel carrying the fix commits (DMBs allocated with folio_alloc() so they are page-backed). Interim: blacklist the smc_loopback / loopback-ism module so SMC-D loopback is not offered, or blacklist smc entirely on nodes not using it.
References
Related entries
- Linux kernel (net/smc): Connect() on an SMC socket takes the destination device pointer out of the dst cache without aCVE-2025-40064 · Linux kernel (net/smc)High
- Linux kernel (net/smc): Tee(2) duplicates an SMC splice pipe buffer without duplicating the private state hanging offCVE-2026-31507 · Linux kernel (net/smc)High
- Linux kernel (net/smc): The SMC socket hashtables are re-initialised at the end of module init, after the protocol andCVE-2026-64005 · Linux kernel (net/smc)High
- Linux kernel (net/smc): On hosts using soft-RoCE, the IB device has no DMA device, and the SMC buffer-mapping pathCVE-2025-39857 · Linux kernel (net/smc)High
- Linux kernel (net/smc): Setsockopt() on an SMC socket copies the option value from user memory while holding the socketCVE-2026-53274 · Linux kernel (net/smc)Medium
- Linux kernel (net/smc): The early link-group cleanup path deletes the list head instead of the link group, so the groupCVE-2021-47536 · Linux kernel (net/smc)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.