GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel SMC-R connection data control (smc_cdc_rx_handler socket lifetime): The CDC receive handler looks the

CVE-2026-64541Kernel, userspace & hypervisorcurated

Impact

The CDC receive handler looks the connection up by token under the link group's lock, drops the lock, and only then dereferences the connection and its socket - holding no reference across the gap. A concurrent close on the local side frees the socket in that window, and the remote peer decides when the CDC message arrives, so a peer on the RDMA fabric times its send against a closing connection to get a use-after-free. The token is carried in the wire message, meaning the peer also chooses which connection to aim at.

Who can reach it

Remote over the SMC-R RDMA link. Requires an established link group with the target, which any peer that completes an SMC handshake has.

What to do

Kernel update pinning the socket across the lock drop. Keep SMC off tenant-reachable paths if it is not deliberately in use.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.