Executive brief
A vulnerability was identified in the Linux kernel's Shared Memory Communications (SMC) protocol, which is used for high-performance data exchange. A flaw in how the system handles network device information during a connection could lead to a system crash or unauthorized memory access. This could allow a local attacker to compromise the stability of the system or potentially access sensitive information.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel's SMC implementation within the 'smc_clc_prfx_set()' function. The issue arises because the function accesses 'sk_dst_get(sk)->dev' without proper RCU (Read-Copy-Update) or RTNL (Routing Netlink) locking during a connection handshake. An attacker with local access could exploit this race condition to trigger a UAF, potentially leading to a kernel crash or arbitrary code execution. The fix involves using '__sk_dst_get()' and 'dst_dev_rcu()' within an 'rcu_read_lock()' block to ensure safe access to the network device structure. Patches have been released in stable kernel versions including 6.18 and backported to earlier stable branches.
Affected products
- Linux Linux Kernel 4.11 to 6.17.3
Timeline
- 2025-09-16: patched: Initial fix commit authored
- 2025-11-12: disclosed: CVE published