Database/Kernel, userspace & hypervisor
Linux kernel SMC-D client (CHID matching against unpopulated ism_dev slot): Slot 0 of the client's ISM device array is
Impact
Slot 0 of the client's ISM device array is reserved for a V1 device and left zeroed when only V2 devices are found. The accepted-CHID matcher compares from index 0 using the CHID alone, so a malicious server replying with CHID 0 matches the empty slot, the client selects a NULL device, and the following lgr_lock dereference faults. The client is the victim here: a hostile SMC server crashes every node that connects to it.
Who can reach it
Remote, from the server side. A malicious or compromised SMC peer answers a V2-only proposal with CHID 0.
What to do
Kernel update rejecting a CHID-0 match against an empty slot. Do not let tenant workloads act as SMC servers for host-level clients, and keep SMC disabled where it is not intentional.
References
Related entries
- Linux kernel pcrypt: padata fallback leaves the parallel completion callback on the child requestCVE-2026-64312 · Linux kernel crypto pcrypt (padata -EBUSY fallback path)High
- Linux kernel RT scheduler: RT_PUSH_IPI can livelock a busy many-core node under softirq loadCVE-2026-64374 · Linux kernel RT scheduler (RT_PUSH_IPI pull logic on non-PREEMPT_RT kernels)High
- Linux kernel libceph: a monmap advertising zero monitors hits a BUG_ON and takes down the client nodeCVE-2026-68155 · Linux kernel libceph (ceph_monmap_decode, zero-monitor monmap)High
- Linux kernel libceph: NULL dereference in CRUSH locality lookup when a parent bucket's type name is missingCVE-2026-68157 · Linux kernel libceph (get_immediate_parent CRUSH type name lookup)High
- Linux kernel (net/tls): A remote peer sends a zero-length TLS 1.3 application_data record - which the RFC explicitlyCVE-2026-72330 · Linux kernel (net/tls)High
- OpenSSL: SSL_set_SSL_CTX mid-handshake leaves a stale slot count, allowing heap OOB read/writeCVE-2026-72897 · OpenSSL TLS server (SSL_set_SSL_CTX certificate-slot array)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.