Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-64541

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
27/07/2026
Última modificación:
27/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket<br /> <br /> smc_cdc_rx_handler() looks up the connection by token under the link<br /> group&amp;#39;s conns_lock, drops the lock, and then dereferences conn and the<br /> smc_sock derived from it, ending in sock_hold(&amp;smc-&gt;sk) inside<br /> smc_cdc_msg_recv(). No reference is held across the lock release.<br /> <br /> The only reference pinning the socket while the connection is<br /> discoverable in the link group is taken in smc_lgr_register_conn()<br /> (sock_hold) and dropped in __smc_lgr_unregister_conn() (sock_put), both<br /> under conns_lock. Once the handler drops conns_lock, a concurrent<br /> close() -&gt; smc_release() -&gt; smc_conn_free() -&gt; smc_lgr_unregister_conn()<br /> can drop that reference and free the smc_sock, so the handler&amp;#39;s later<br /> sock_hold() runs on freed memory:<br /> <br /> WARNING: lib/refcount.c:25 at refcount_warn_saturate<br /> Workqueue: rxe_wq do_work<br /> refcount_warn_saturate (lib/refcount.c:25)<br /> smc_cdc_msg_recv (net/smc/smc_cdc.c:430)<br /> smc_cdc_rx_handler (net/smc/smc_cdc.c:502)<br /> smc_wr_rx_tasklet_fn (net/smc/smc_wr.c:445)<br /> tasklet_action_common (kernel/softirq.c:938)<br /> handle_softirqs (kernel/softirq.c:622)<br /> Kernel panic - not syncing: panic_on_warn set<br /> <br /> Only SMC-R is affected. The SMC-D receive tasklet is stopped by<br /> tasklet_kill(&amp;conn-&gt;rx_tsklet) in smc_conn_free() before the connection<br /> is unregistered, so it cannot run concurrently with the free.<br /> <br /> Take the socket reference while still holding conns_lock, so the<br /> registration reference can no longer be the last one, and drop it once<br /> the handler is done.

Impacto