Executive brief
A vulnerability was found in the Linux kernel's Shared Memory Communications (SMC) protocol, which is used for high-performance data exchange. A flaw in how the system handles network device references could allow a local attacker to cause a system crash or potentially execute unauthorized code. This issue primarily impacts system stability and the reliability of high-speed networking operations.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel's SMC implementation within the __pnet_find_base_ndev() function. The root cause is a race condition where a net_device pointer is fetched via sk_dst_get() but its reference count is not properly incremented before the routine attempts to acquire the RTNL lock. Consequently, the device can be freed or replaced by a blackhole_netdev while the code is still attempting to use it. This affects both smc_pnet_find_ism_resource() and smc_pnet_find_roce_resource(). A local attacker can trigger this during a connect() system call to cause a kernel panic or potentially achieve privilege escalation. The fix involves using __sk_dst_get() and dst_dev_rcu() to properly manage device reference counts.
Affected products
- Linux Linux Kernel 0afff91c6f5ecef27715ea71e34dc2baacba1060
Timeline
- 2025-09-16: other: Patch authored
- 2025-10-28: disclosed: CVE published