CVE-2026-80980
Gravedad CVSS v3.1:
CRÍTICA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
11/09/2026
Última modificación:
03/10/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
net/smc: stop killed, freed and out_of_sync sharing a byte<br />
<br />
The three connection state flags are single-bit bitfields, so they occupy<br />
one byte of struct smc_connection and every store to one is a<br />
read-modify-write of the other two:<br />
<br />
u8 killed : 1;<br />
u8 freed : 1;<br />
u8 out_of_sync : 1;<br />
<br />
They are not written under a common lock. smc_cdc_msg_validate() sets<br />
out_of_sync from the receive tasklet, while smc_conn_kill() sets killed<br />
from process context under lock_sock(), and the receive path does not defer<br />
to the backlog when the socket is owned -- smc_cdc_msg_recv() takes only<br />
bh_lock_sock().<br />
<br />
Give each flag its own byte so a store no longer touches its neighbours.<br />
All readers test them as booleans and are unchanged. struct smc_connection<br />
grows by two bytes.
Impacto
Puntuación base 3.x
9.80
Gravedad 3.x
CRÍTICA


