Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-64048

Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
19/07/2026
Última modificación:
30/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot<br /> <br /> On the SMC-D client, slot 0 of ini-&gt;ism_dev[]/ini-&gt;ism_chid[] is<br /> reserved for an SMC-Dv1 device. smc_find_ism_v2_device_clnt()<br /> populates V2 entries starting at index 1, so when no V1 device is<br /> selected slot 0 is left in its kzalloc()&amp;#39;ed state with ism_dev[0] ==<br /> NULL and ism_chid[0] == 0.<br /> <br /> smc_v2_determine_accepted_chid() then matches the peer&amp;#39;s CHID against<br /> the array starting from index 0 using the CHID alone. A malicious<br /> peer replying to a SMC-Dv2-only proposal with d1.chid == 0 matches<br /> the empty slot, ini-&gt;ism_selected becomes 0, and the subsequent<br /> ism_dev[0]-&gt;lgr_lock dereference in smc_conn_create() faults at<br /> offsetof(struct smcd_dev, lgr_lock) == 0x68:<br /> <br /> BUG: KASAN: null-ptr-deref in _raw_spin_lock_bh+0x79/0xe0<br /> Write of size 4 at addr 0000000000000068 by task exploit/144<br /> Call Trace:<br /> _raw_spin_lock_bh<br /> smc_conn_create (net/smc/smc_core.c:1997)<br /> __smc_connect (net/smc/af_smc.c:1447)<br /> smc_connect (net/smc/af_smc.c:1720)<br /> __sys_connect<br /> __x64_sys_connect<br /> do_syscall_64<br /> <br /> Require ism_dev[i] to be non-NULL before accepting a CHID match.