Executive brief
The Linux kernel's shared memory communication (SMC) networking module contains a race condition that can cause system crashes. When the SMC port event handler runs concurrently with linkgroup list modifications, unprotected list iteration can lead to null pointer dereference and kernel panic, disrupting network connectivity and causing service outages.
Technical details
The vulnerability is a race condition in the net/smc subsystem's smcr_port_add function. The smcr_port_add function iterates over smc_lgr_list.list without holding the protective lock, while concurrent threads may be adding or removing linkgroup entries from the same list. This unsynchronized access can cause the iteration to follow invalid pointers, resulting in a kernel NULL pointer dereference and crash. The vulnerable code path is triggered during SMC InfiniBand port event processing in the smc_ib_port_event_work handler. The fix involves protecting the list iteration with smc_lgr_list.lock to ensure thread-safe access.
Affected products
- Linux Linux kernel prior to fix (SMC module in net/smc)
Timeline
- 2025-12-30: disclosed