CVE-2026-52941
Gravedad CVSS v3.1:
MEDIA
Tipo:
CWE-476
Desreferencia a puntero nulo (NULL)
Fecha de publicación:
24/06/2026
Última modificación:
08/07/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
net/smc: avoid NULL deref of conn->lnk in smc_msg_event tracepoint<br />
<br />
The smc_msg_event tracepoint class, shared by smc_tx_sendmsg and<br />
smc_rx_recvmsg, unconditionally dereferences smc->conn.lnk:<br />
<br />
__string(name, smc->conn.lnk->ibname)<br />
<br />
conn->lnk is only set for SMC-R; for SMC-D it is NULL. Other code on<br />
these paths already handles this (e.g. !conn->lnk in<br />
SMC_STAT_RMB_TX_SIZE_SMALL()). With the tracepoint enabled, the first<br />
sendmsg()/recvmsg() on an SMC-D socket crashes:<br />
<br />
Oops: general protection fault, probably for non-canonical address<br />
KASAN: null-ptr-deref in range [...]<br />
RIP: 0010:strlen+0x1e/0xa0<br />
Call Trace:<br />
trace_event_raw_event_smc_msg_event (net/smc/smc_tracepoint.h:44)<br />
smc_rx_recvmsg (net/smc/smc_rx.c:515)<br />
smc_recvmsg (net/smc/af_smc.c:2859)<br />
__sys_recvfrom (net/socket.c:2315)<br />
__x64_sys_recvfrom (net/socket.c:2326)<br />
do_syscall_64<br />
<br />
The faulting address 0x3e0 is offsetof(struct smc_link, ibname),<br />
confirming the NULL ->lnk deref. Enabling the tracepoint requires<br />
root, but the trigger itself is unprivileged: socket(AF_SMC, ...) has<br />
no capability check, and SMC-D negotiation needs no admin step on<br />
s390 or on x86 with the loopback ISM device loaded.<br />
<br />
Log an empty device name for SMC-D instead of dereferencing NULL.
Impacto
Puntuación base 3.x
5.50
Gravedad 3.x
MEDIA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (incluyendo) | 6.1.175 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (incluyendo) | 6.6.142 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (incluyendo) | 6.12.92 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (incluyendo) | 6.18.34 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (incluyendo) | 7.0.11 (excluyendo) |
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/561cf66fa9b6c86dfe4e687d2d1aeaaa6739917f
- https://git.kernel.org/stable/c/68200112534bb2acd1d7117dc2d5c124868d866d
- https://git.kernel.org/stable/c/720c76b930c52cd58f50eb6b10569d03dccc7959
- https://git.kernel.org/stable/c/7bf563badd37cb796df5477d2b78bb64148a1268
- https://git.kernel.org/stable/c/b706d6d76a2a2793fe5ad0fbc2a75b6a460094ef
- https://git.kernel.org/stable/c/d2ea0b8aef8746e147602eac87ca8538f4bc7e66



