Executive brief
The Linux kernel's SMC (Shared Memory Communications) protocol implementation contains a synchronization flaw that can trigger a system panic when establishing redundant network links. An attacker with local or network access can exploit this to cause a denial of service, crashing the system or making it unresponsive. This affects servers that rely on SMC for high-performance network connectivity.
Technical details
The vulnerability exists in the SMC protocol's link management code (smc_llc_srv_add_link function) which lacks proper mutex protection when adding new links to a link group. When a server attempts to establish a second link, the unprotected function can race with other operations protected by llc_conf_mutex, corrupting internal data structures. The crash manifests as a page fault in the InfiniBand memory region allocation function (ib_alloc_mr), indicating memory corruption in the SMC link setup path. The vulnerability is triggered during link group configuration and can be exploited by local processes or remote systems initiating SMC connections. A patch that properly protects the smc_llc_srv_add_link function with appropriate locking is available.
Affected products
- Linux Linux kernel <UNKNOWN>
Timeline
- 2025-12-30: disclosed