Database/Kernel, userspace & hypervisor
Linux kernel SMC-R connection data control (smc_cdc_rx_handler socket lifetime): The CDC receive handler looks the
Impact
The CDC receive handler looks the connection up by token under the link group's lock, drops the lock, and only then dereferences the connection and its socket - holding no reference across the gap. A concurrent close on the local side frees the socket in that window, and the remote peer decides when the CDC message arrives, so a peer on the RDMA fabric times its send against a closing connection to get a use-after-free. The token is carried in the wire message, meaning the peer also chooses which connection to aim at.
Who can reach it
Remote over the SMC-R RDMA link. Requires an established link group with the target, which any peer that completes an SMC handshake has.
What to do
Kernel update pinning the socket across the lock drop. Keep SMC off tenant-reachable paths if it is not deliberately in use.
References
Related entries
- Linux kernel (net/xfrm): The same ownership-marker bug as CVE-2026-53363, in the other IPTFS frag-transfer helper.CVE-2026-64566 · Linux kernel (net/xfrm)Critical
- Linux kernel libceph: malicious OSD triggers out-of-bounds reads in RBD lock-info decodeCVE-2026-68082 · Linux kernel libceph (decode_lockers() in cls_lock_client.c)Critical
- Linux libceph: CRUSH map with a zero bucket type makes the mapper index the OSD weight array negativelyCVE-2026-68154 · Linux kernel libceph (crush_decode, CRUSH map bucket type validation)Critical
- Linux libceph: stale authorizer buffer pointer after ticket refresh causes a use-after-free on msgr1 reconnectCVE-2026-68156 · Linux kernel libceph (ceph_x authorizer buffer, ceph_auth_handshake stale pointer)Critical
- Linux libceph: integer overflow in osdmap decoding defeats the bounds check and reads out of boundsCVE-2026-68158 · Linux kernel libceph (decode_new_up_state_weight, osdmap length arithmetic)Critical
- Linux kernel libceph: unbounded pg_temp length lets a malicious monitor cause a stack out-of-bounds writeCVE-2026-68159 · Linux kernel libceph (OSDMap pg_temp / pg_upmap / pg_upmap_items decode)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.