Database/Kernel, userspace & hypervisor
Linux kernel (net/smc): Connect() on an SMC socket takes the destination device pointer out of the dst cache without a
Impact
Connect() on an SMC socket takes the destination device pointer out of the dst cache without a reference and only then grabs RTNL, so a device that goes away in that window is dereferenced after free during ISM/RoCE device selection. KASAN confirms the use-after-free read in __pnet_find_base_ndev; a tenant that races connect() against interface teardown reads and can corrupt freed kernel memory.
Who can reach it
Local and unprivileged: loop connect() on AF_SMC sockets while a netdev is being removed - trivial for a tenant that controls its own veth or has a container being torn down alongside. socket(AF_SMC, ...) requires no capability and autoloads the smc module via the net-pf-43 alias, so no /dev/infiniband access is needed to reach the pnetid lookup.
What to do
Boot a kernel carrying the fix commits (holds the device reference across smc_pnet_find_ism_resource / smc_pnet_find_roce_resource). Interim: blacklist the smc module or deny socket family 43 to tenants.
References
Related entries
- Linux kernel (net/smc): Tee(2) duplicates an SMC splice pipe buffer without duplicating the private state hanging offCVE-2026-31507 · Linux kernel (net/smc)High
- Linux kernel (net/smc): The SMC socket hashtables are re-initialised at the end of module init, after the protocol andCVE-2026-64005 · Linux kernel (net/smc)High
- Linux kernel (net/smc): On hosts using soft-RoCE, the IB device has no DMA device, and the SMC buffer-mapping pathCVE-2025-39857 · Linux kernel (net/smc)High
- Linux kernel (net/smc): Setsockopt() on an SMC socket copies the option value from user memory while holding the socketCVE-2026-53274 · Linux kernel (net/smc)Medium
- Linux kernel (net/smc): The early link-group cleanup path deletes the list head instead of the link group, so the groupCVE-2021-47536 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): When an SMC-R link is torn down, the kernel moves the QP to Error state and then destroys theCVE-2022-48673 · Linux kernel (net/smc)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.