CVE-2026-52941
Severity CVSS v4.0:
Pending analysis
Type:
CWE-476
NULL Pointer Dereference
Publication date:
24/06/2026
Last modified:
08/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
net/smc: avoid NULL deref of conn->lnk in smc_msg_event tracepoint<br />
<br />
The smc_msg_event tracepoint class, shared by smc_tx_sendmsg and<br />
smc_rx_recvmsg, unconditionally dereferences smc->conn.lnk:<br />
<br />
__string(name, smc->conn.lnk->ibname)<br />
<br />
conn->lnk is only set for SMC-R; for SMC-D it is NULL. Other code on<br />
these paths already handles this (e.g. !conn->lnk in<br />
SMC_STAT_RMB_TX_SIZE_SMALL()). With the tracepoint enabled, the first<br />
sendmsg()/recvmsg() on an SMC-D socket crashes:<br />
<br />
Oops: general protection fault, probably for non-canonical address<br />
KASAN: null-ptr-deref in range [...]<br />
RIP: 0010:strlen+0x1e/0xa0<br />
Call Trace:<br />
trace_event_raw_event_smc_msg_event (net/smc/smc_tracepoint.h:44)<br />
smc_rx_recvmsg (net/smc/smc_rx.c:515)<br />
smc_recvmsg (net/smc/af_smc.c:2859)<br />
__sys_recvfrom (net/socket.c:2315)<br />
__x64_sys_recvfrom (net/socket.c:2326)<br />
do_syscall_64<br />
<br />
The faulting address 0x3e0 is offsetof(struct smc_link, ibname),<br />
confirming the NULL ->lnk deref. Enabling the tracepoint requires<br />
root, but the trigger itself is unprivileged: socket(AF_SMC, ...) has<br />
no capability check, and SMC-D negotiation needs no admin step on<br />
s390 or on x86 with the loopback ISM device loaded.<br />
<br />
Log an empty device name for SMC-D instead of dereferencing NULL.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 6.1.175 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.142 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.92 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.18.34 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (including) | 7.0.11 (excluding) |
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/561cf66fa9b6c86dfe4e687d2d1aeaaa6739917f
- https://git.kernel.org/stable/c/68200112534bb2acd1d7117dc2d5c124868d866d
- https://git.kernel.org/stable/c/720c76b930c52cd58f50eb6b10569d03dccc7959
- https://git.kernel.org/stable/c/7bf563badd37cb796df5477d2b78bb64148a1268
- https://git.kernel.org/stable/c/b706d6d76a2a2793fe5ad0fbc2a75b6a460094ef
- https://git.kernel.org/stable/c/d2ea0b8aef8746e147602eac87ca8538f4bc7e66



