Junglewise Threat Intelligence

CVE-2023-54237: Linux kernel SMC network protocol panic due to unprotected link addition

CVE-2023-54237 · Severity: critical · CVSS 9.8 · Published 2025-12-30

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's SMC (Shared Memory Communications) protocol implementation contains a synchronization flaw that can trigger a system panic when establishing redundant network links. An attacker with local or network access can exploit this to cause a denial of service, crashing the system or making it unresponsive. This affects servers that rely on SMC for high-performance network connectivity.

Technical details

The vulnerability exists in the SMC protocol's link management code (smc_llc_srv_add_link function) which lacks proper mutex protection when adding new links to a link group. When a server attempts to establish a second link, the unprotected function can race with other operations protected by llc_conf_mutex, corrupting internal data structures. The crash manifests as a page fault in the InfiniBand memory region allocation function (ib_alloc_mr), indicating memory corruption in the SMC link setup path. The vulnerability is triggered during link group configuration and can be exploited by local processes or remote systems initiating SMC connections. A patch that properly protects the smc_llc_srv_add_link function with appropriate locking is available.

Affected products

  • Linux Linux kernel <UNKNOWN>

Timeline

  • 2025-12-30: disclosed

Related threats