Junglewise Threat Intelligence

CVE-2026-23450: Linux Kernel use-after-free in smc_tcp_syn_recv_sock

CVE-2026-23450 · Severity: critical · CVSS 9.8 · Published 2026-04-03

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Shared Memory Communications (SMC) networking protocol could allow a remote attacker to crash the system or potentially execute unauthorized code. The issue occurs when the system handles incoming network connections while a listening socket is simultaneously being closed, leading to a memory management error. This could result in a complete service outage or a compromise of the affected server.

Technical details

A race condition exists in net/smc/af_smc.c within the smc_tcp_syn_recv_sock() function. When an SMC listening socket is closed concurrently with an incoming TCP SYN packet, the 'sk_user_data' pointer can be set to NULL or the underlying 'smc_sock' object can be freed while still being accessed in the softirq context. This occurs because the TCP listening socket (clcsock) and the SMC socket have independent reference counts, and the TCP stack's reference on clcsock does not prevent the smc_sock from being released. Attackers can trigger this via the SYN cookie path or normal TCP request checking. The fix involves implementing RCU-protected access to 'sk_user_data' and using 'refcount_inc_not_zero' to safely pin the socket memory.

Affected products

  • Linux Linux Kernel 5.15.174 to 5.15.203, 5.18 to 6.1.167, 6.2 to 6.6.130, 6.7 to 6.12.78, 6.13 to 6.18.20, 6.19 to 6.19.10, 7.0-rc1 to 7.0-rc5

Timeline

  • 2026-03-12: patched: Initial patch submitted by Jiayuan Chen
  • 2026-04-03: advisory: CVE-2026-23450 published

References

Related threats