CVE-2026-80980

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/09/2026
Last modified:
03/10/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> net/smc: stop killed, freed and out_of_sync sharing a byte<br /> <br /> The three connection state flags are single-bit bitfields, so they occupy<br /> one byte of struct smc_connection and every store to one is a<br /> read-modify-write of the other two:<br /> <br /> u8 killed : 1;<br /> u8 freed : 1;<br /> u8 out_of_sync : 1;<br /> <br /> They are not written under a common lock. smc_cdc_msg_validate() sets<br /> out_of_sync from the receive tasklet, while smc_conn_kill() sets killed<br /> from process context under lock_sock(), and the receive path does not defer<br /> to the backlog when the socket is owned -- smc_cdc_msg_recv() takes only<br /> bh_lock_sock().<br /> <br /> Give each flag its own byte so a store no longer touches its neighbours.<br /> All readers test them as booleans and are unchanged. struct smc_connection<br /> grows by two bytes.