Executive brief
A vulnerability was identified in the Linux kernel's Shared Memory Communications (SMC) protocol, which is used for high-performance data transfers. A flaw in how the system handles network destination information could lead to a system crash or unauthorized memory access. This could potentially impact the stability and security of servers utilizing SMC for network traffic.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel's SMC implementation within the 'smc_clc_prfx_match' function in 'net/smc/smc_clc.c'. The issue arises because 'smc_clc_prfx_match' is called from 'smc_listen_work' without proper RCU or RTNL locking, leading to a race condition when accessing 'sk_dst_get(sk)->dev'. An attacker could potentially exploit this race condition to trigger a UAF state. The fix involves migrating to '__sk_dst_get()' and 'dst_dev_rcu()' to ensure safe RCU-protected access to the network device. Patches have been released in various stable kernel branches including 6.18 and backported to earlier versions.
Affected products
- Linux Linux Kernel 4.11 to 6.17.3
Timeline
- 2025-09-16: patched: Initial fix commit authored
- 2025-11-12: disclosed: CVE published