Database/Kernel, userspace & hypervisor
Linux kernel (net/smc): The CLC prefix-match check on the listen path dereferences the destination cache entry's
Impact
The CLC prefix-match check on the listen path dereferences the destination cache entry's net_device outside RCU and outside RTNL, so a device being torn down concurrently leaves the handshake reading freed memory. A peer connecting during any interface churn - VF teardown, bond member removal, container netns exit - gets a use-after-free on the server side of the SMC handshake.
Who can reach it
Remote-driven: smc_clc_prfx_match() runs inside smc_listen_work while processing an inbound CLC proposal, so an unauthenticated connecting peer supplies the timing. The race partner is ordinary netdev churn, which is constant on a multi-tenant node (per-container veths, SR-IOV VFs coming and going). Requires the smc module loaded, which any unprivileged socket(AF_SMC, ...) achieves.
What to do
Boot a kernel carrying the fix commits (uses __sk_dst_get()/dst_dev_rcu() under RCU). Interim: blacklist the smc module on nodes not using SMC-R, and avoid exposing SMC listeners to untrusted peers.
References
Related entries
- Linux kernel (net/smc): The CDC send-completion handler takes a lock inside an smc_sock that close() has already freedCVE-2021-46925 · Linux kernel (net/smc)High
- Linux kernel (net/smc): An unprivileged tenant that opens an AF_SMC socket, registers it with epoll, and lets theCVE-2022-48721 · Linux kernel (net/smc)High
- Linux kernel (net/smc): Closing an SMC socket can leave the internal TCP kernel socket with its timers still armed andCVE-2023-53781 · Linux kernel (net/smc)High
- Linux kernel (net/smc): SMC-D loopback registers DMBs (the direct memory buffers a peer reads and writes) out ofCVE-2025-40012 · Linux kernel (net/smc)High
- Linux kernel (net/smc): Connect() on an SMC socket takes the destination device pointer out of the dst cache without aCVE-2025-40064 · Linux kernel (net/smc)High
- Linux kernel (net/smc): Tee(2) duplicates an SMC splice pipe buffer without duplicating the private state hanging offCVE-2026-31507 · Linux kernel (net/smc)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.