Database/Kernel, userspace & hypervisor
Linux kernel (net/smc): The SMC socket hashtables are re-initialised at the end of module init, after the protocol and
Impact
The SMC socket hashtables are re-initialised at the end of module init, after the protocol and socket family have already been registered. Sockets created in that window get their hash-list heads zeroed out from under them, leaving a corrupted list the kernel keeps walking and writing - memory corruption seeded at module load time.
Who can reach it
Local and unprivileged, and the trigger is the module autoload itself: socket(AF_SMC, ...) from an unprivileged process makes the kernel request the smc module through the net-pf-43 alias with no capability check, and a second thread racing socket() calls against that load lands in the window between sock_register() and the hashtable re-init. A tenant container can arrange this deliberately.
What to do
Boot a kernel carrying the fix commits (drops the redundant INIT_HLIST_HEAD calls). Interim: pre-load the smc module at boot on nodes that need it so no tenant can race a cold autoload, or blacklist it outright (install smc /bin/false) where SMC is unused.
References
Related entries
- Linux kernel (net/smc): On hosts using soft-RoCE, the IB device has no DMA device, and the SMC buffer-mapping pathCVE-2025-39857 · Linux kernel (net/smc)High
- Linux kernel (net/smc): Setsockopt() on an SMC socket copies the option value from user memory while holding the socketCVE-2026-53274 · Linux kernel (net/smc)Medium
- Linux kernel (net/smc): The early link-group cleanup path deletes the list head instead of the link group, so the groupCVE-2021-47536 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): When an SMC-R link is torn down, the kernel moves the QP to Error state and then destroys theCVE-2022-48673 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): When an incoming connection tries SMC-Rv2 and device setup fails, the listener does not resetCVE-2023-53382 · Linux kernel (net/smc)Critical
- Linux kernel (net/smc): On the server side of the SMC-R LLC handshake, adding a second link to a link group runsCVE-2023-54237 · Linux kernel (net/smc)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.