Executive brief
The Linux kernel's SMC (Shared Memory Communication) protocol implementation contains a use-after-free vulnerability in the link setup function. An attacker on the network could trigger a denial of service or potentially execute code by exploiting improper memory handling during the link negotiation process, disrupting communication between systems relying on SMC for performance optimization.
Technical details
A use-after-free vulnerability exists in smc_llc_srv_add_link() where a pointer to a queue entry (add_llc) is retained after the entry is freed by smc_llc_flow_qentry_del(). The vulnerable code path occurs when a link without a shared v2 receive buffer attempts to use the freed add_llc pointer to read remote key information via smc_llc_save_add_link_rkeys(). This is a memory safety bug triggered during SMC link negotiation when certain receive buffer configurations are present. The vulnerability requires network reachability to an SMC endpoint and affects kernel versions prior to a specific patch (referenced as "Fixes: commit"). A fix is available in patched kernel versions.
Affected products
- Linux Linux Kernel prior to fix (affects 7.2.0-rc5 and earlier)
Timeline
- 2026-09-11: disclosed