Database/Kernel, userspace & hypervisor
Linux kernel (net/smc): Setsockopt() on an SMC socket copies the option value from user memory while holding the socket
Impact
Setsockopt() on an SMC socket copies the option value from user memory while holding the socket lock, so a tenant pointing optval at a userfaultfd- or FUSE-backed page can hold that lock forever. Combined with asynchronous shutdown work, this drains the kernel worker pool and trips the hung-task watchdog - one tenant's process wedges kworkers for every workload on the node.
Who can reach it
Local and fully unprivileged: register a userfaultfd region (or mmap a FUSE-backed file where unprivileged userfaultfd is disabled), pass it as optval to setsockopt() on an AF_SMC socket, then call shutdown() from another thread. socket(AF_SMC, ...) autoloads the module with no capability check, so any tenant container reaches it. This is a noisy-neighbour outage, not a corruption bug - but it is a whole-node one.
What to do
Boot a kernel carrying the fix commits (moves the user copy outside lock_sock). Interim: blacklist the smc module or deny socket family 43 in tenant seccomp profiles; disabling unprivileged userfaultfd (vm.unprivileged_userfaultfd=0) narrows but does not close the path, since FUSE-backed memory works too.
References
Related entries
- Linux kernel (net/smc): The early link-group cleanup path deletes the list head instead of the link group, so the groupCVE-2021-47536 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): When an SMC-R link is torn down, the kernel moves the QP to Error state and then destroys theCVE-2022-48673 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): When an incoming connection tries SMC-Rv2 and device setup fails, the listener does not resetCVE-2023-53382 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): On the server side of the SMC-R LLC handshake, adding a second link to a link group runsCVE-2023-54237 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): The server-side listen worker frees a connection outside the socket lock, so smc_conn_free()CVE-2024-56640 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): A link-down work item can be queued before the link group is freed but run after, so the workerCVE-2024-56718 · Linux kernel (net/smc)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.