Database/Kernel, userspace & hypervisor
Linux kernel (net/smc): Link-group termination drops conns_lock after finding a connection but before taking a socket
Impact
Link-group termination drops conns_lock after finding a connection but before taking a socket reference, so a concurrent close can free the socket the termination worker is about to write to. KASAN confirms a slab-use-after-free write from smc_lgr_terminate_work - a fabric event that overlaps a tenant closing its connection turns into host memory corruption.
Who can reach it
Reachable whenever link-group termination overlaps connection close. Termination is driven from the fabric side (link down, device event, peer-initiated teardown) while the close is an unprivileged tenant operation, so neither half needs privilege. The write lands in a kworker, so the blast radius is the node, not the tenant. Requires SMC-R in use; the module autoloads from an unprivileged socket(AF_SMC, ...).
What to do
Boot a kernel carrying the fix commits (takes the socket reference while conns_lock still protects the tree entry). Interim: blacklist the smc module on nodes not running SMC-R, and keep untrusted tenants off the fabric segment that can drive link-group termination.
References
Related entries
- Linux kernel (net/smc): The IB port-up handler walks the global link-group list without holding its lock, so a fabricCVE-2023-54318 · Linux kernel (net/smc)High
- Linux kernel (net/smc): The CLC prefix-match check on the listen path dereferences the destination cache entry'sCVE-2025-40168 · Linux kernel (net/smc)High
- Linux kernel (net/smc): The CDC send-completion handler takes a lock inside an smc_sock that close() has already freedCVE-2021-46925 · Linux kernel (net/smc)High
- Linux kernel (net/smc): An unprivileged tenant that opens an AF_SMC socket, registers it with epoll, and lets theCVE-2022-48721 · Linux kernel (net/smc)High
- Linux kernel (net/smc): Closing an SMC socket can leave the internal TCP kernel socket with its timers still armed andCVE-2023-53781 · Linux kernel (net/smc)High
- Linux kernel (net/smc): SMC-D loopback registers DMBs (the direct memory buffers a peer reads and writes) out ofCVE-2025-40012 · Linux kernel (net/smc)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.