CVE-2026-64541
Received Received - Intake

Use-After-Free in Linux Kernel SMC Subsystem

Vulnerability report for CVE-2026-64541, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-27

Last updated on: 2026-07-27

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket smc_cdc_rx_handler() looks up the connection by token under the link group's conns_lock, drops the lock, and then dereferences conn and the smc_sock derived from it, ending in sock_hold(&smc->sk) inside smc_cdc_msg_recv(). No reference is held across the lock release. The only reference pinning the socket while the connection is discoverable in the link group is taken in smc_lgr_register_conn() (sock_hold) and dropped in __smc_lgr_unregister_conn() (sock_put), both under conns_lock. Once the handler drops conns_lock, a concurrent close() -> smc_release() -> smc_conn_free() -> smc_lgr_unregister_conn() can drop that reference and free the smc_sock, so the handler's later sock_hold() runs on freed memory: WARNING: lib/refcount.c:25 at refcount_warn_saturate Workqueue: rxe_wq do_work refcount_warn_saturate (lib/refcount.c:25) smc_cdc_msg_recv (net/smc/smc_cdc.c:430) smc_cdc_rx_handler (net/smc/smc_cdc.c:502) smc_wr_rx_tasklet_fn (net/smc/smc_wr.c:445) tasklet_action_common (kernel/softirq.c:938) handle_softirqs (kernel/softirq.c:622) Kernel panic - not syncing: panic_on_warn set Only SMC-R is affected. The SMC-D receive tasklet is stopped by tasklet_kill(&conn->rx_tsklet) in smc_conn_free() before the connection is unregistered, so it cannot run concurrently with the free. Take the socket reference while still holding conns_lock, so the registration reference can no longer be the last one, and drop it once the handler is done.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-27
Last Modified
2026-07-27
Generated
2026-07-28
AI Q&A
2026-07-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux_kernel linux_kernel to 416baaa9-dc9f-4396-8d5f-8c081fb06d67 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a use-after-free (UAF) vulnerability in the Linux kernel's SMC (Socket Direct) protocol implementation. It occurs in the smc_cdc_rx_handler() function where a socket reference is accessed after being freed. The issue happens because the function drops a lock before properly pinning the socket, allowing a concurrent close operation to free the socket before the handler can safely use it.

Detection Guidance

This vulnerability is specific to the Linux kernel's SMC (Socket Direct) implementation and may not have direct detection commands. Monitor kernel logs for warnings like 'refcount_warn_saturate' or 'Kernel panic' related to SMC-R. Check for crashes in network-related tasklets or panics with 'smc_cdc_rx_handler' in the stack trace.

Impact Analysis

This vulnerability could lead to kernel memory corruption, crashes, or privilege escalation. An attacker could exploit it to cause a denial-of-service (system panic) or potentially execute arbitrary code in the kernel context. Systems using SMC-R (Socket Direct RDMA) are specifically affected.

Mitigation Strategies

Apply the latest Linux kernel patches that address this issue. If using SMC-R, consider disabling it temporarily if patches are unavailable. Monitor kernel logs for related crashes or warnings. Update to a kernel version where this issue is resolved.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-64541. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart