Database/Kernel, userspace & hypervisor
Linux kernel SMC (early link-group access on CLC decline in smc_clc_wait_msg): A peer can send a CLC decline before the
Impact
A peer can send a CLC decline before the connection has been attached to a link group, and the decline handler updates link-group-level state that does not exist yet. The remote side chooses the timing, so an unauthenticated peer declines early and dereferences the unset link group on the node it is talking to.
Who can reach it
Remote, unauthenticated, during SMC handshake - send a decline before link-group setup completes.
What to do
Kernel update guarding the link-group update on the link group existing. Keep SMC off tenant-reachable interfaces if it is not deliberately used.
References
Related entries
- Netty: client TLS silently skips hostname verification when a plain X509TrustManager is suppliedCVE-2026-50010 · Netty (SimpleTrustManagerFactory / X509TrustManagerWrapper hostname verification)High
- Linux kernel (net/tls): When kTLS RX offload fails at tls_dev_add, the rollback frees the software context but neverCVE-2026-52974 · Linux kernel (net/tls)High
- OpenSSL DTLS: buffering future-epoch records retains a full 16 KB read buffer each, ~1200x memory amplificationCVE-2026-54874 · OpenSSL DTLS record layer (future-epoch record buffering during handshake)High
- OpenSSL: memory leak per handshake when a server staples an OCSP response with no entriesCVE-2026-54876 · OpenSSL X.509 verification (OCSP stapled-response check, X509_V_FLAG_OCSP_RESP_CHECK)High
- libssh: incorrect AES-GCM finalization removes integrity protection on SSH sessionsCVE-2026-59847 · libssh (AES-GCM finalization check, OpenSSL backend)High
- Xen (vRTC): Out-of-bounds read in vRTC emulation - hypervisor memory disclosure to a guestCVE-2026-62430 · Xen (vRTC)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.