Database/Kernel, userspace & hypervisor
Linux kernel (net/ipv4): A child socket created from an inbound handshake is inserted into the TCP hash table before
Impact
A child socket created from an inbound handshake is inserted into the TCP hash table before its IPv6 private-data pointer is fixed up, so other CPUs can find and use a socket that still points at the listener's ipv6_pinfo. A remote peer that opens connections to any listener - including the SMC/MPTCP paths that share this code - drives other CPUs into type-confused socket state.
Who can reach it
Remote and pre-authentication: the window is inside tcp_v4_syn_recv_sock / tcp_v6_syn_recv_sock during the three-way handshake, so ordinary connection traffic to any TCP listener on the node is enough, with no credentials. This is core TCP rather than an optional module - it surfaced in this seam because net/smc/af_smc.c is one of the callers - so every node is exposed regardless of whether SMC or RDMA is in use.
What to do
Boot a kernel carrying the fix commits (moves the IPv6 child fixup into tcp_v6_mapped_child_init, before ehash insertion). There is no meaningful interim control - the path is core TCP accept handling; patch and reboot.
References
Related entries
- Linux kernel mlx5_core RX datapath (striding RQ, page_pool): A regression introduced by the fix for CVE-2025-40350CVE-2026-43465 · Linux kernel mlx5_core RX datapath (striding RQ, page_pool)Critical
- Linux kernel nvmet-tcp - ICReq/teardown race and data-digest error paths: Three lifecycle bugs an initiator can driveCVE-2026-46135 · Linux kernel nvmet-tcp - ICReq/teardown race and data-digest error pathsCritical
- Linux kernel (net/rds): If RDS/IB queue-pair setup fails after the send ring is allocated but before the receive ringCVE-2026-53355 · Linux kernel (net/rds)Critical
- Linux kernel (net/xfrm): IPTFS fragment consumption loses the shared-page marker, so ESP concludes the payload pagesCVE-2026-53363 · Linux kernel (net/xfrm)Critical
- Linux kernel - LIO iSCSI target CHAP authentication, drivers/target/iscsi/iscsi_target_auth.cCVE-2026-63886 · Linux kernel - LIO iSCSI target CHAP authentication, drivers/target/iscsi/iscsi_target_auth.cCritical
- Linux kernel (net/tls): A particular kTLS ring state builds a scatterlist whose chain link points directly at anotherCVE-2026-64046 · Linux kernel (net/tls)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.