CVE-2026-80984
Received Received - Intake

NULL Pointer Dereference in Linux Kernel SMC Protocol

Vulnerability report for CVE-2026-80984, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: net/smc: do not dereference an unset send buffer on the SMC-D teardown path smc_close_stream_wait() calls smc_tx_prepared_sends() from inside its sk_wait_event() condition, and sk_wait_event() evaluates that condition once with the socket lock released. smcd_buf_detach() clears conn->sndbuf_desc from smc_conn_kill() under lock_sock(), so a link group terminating while a socket waits there leaves the helper dereferencing NULL, faulting out of close(). SIOCOUTQ reads the field by hand, and smc_close_cancel_work() drops the lock across two cancel_*_sync() calls. Sample the pointer once in the helper, report nothing prepared while it is unset, and bound the ioctl the same way. The receive tasklet dereferences the field directly in smc_cdc_msg_recv_action(), not through this helper; 1/2 is what keeps it from running that late.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a NULL pointer dereference in the SMC (Socket Messaging Channel) subsystem during teardown. The issue occurs when smc_close_stream_wait() calls smc_tx_prepared_sends() while the socket lock is released, allowing smcd_buf_detach() to clear the send buffer descriptor under lock_sock(). This can lead to a kernel crash when the helper function dereferences a NULL pointer.

Detection Guidance

This vulnerability is specific to the Linux kernel's SMC (Socket Messaging Connections) subsystem and may not have direct detection commands. Monitor kernel logs for NULL pointer dereference errors in SMC-related operations or socket close failures. Check for crashes in network services using SMC with commands like dmesg | grep -i smc or journalctl -k | grep -i smc.

Impact Analysis

This vulnerability could cause system instability or crashes when terminating network connections using SMC-D (Shared Memory Communications over RDMA). It may lead to denial-of-service conditions, requiring a system reboot to restore normal operation.

Compliance Impact

This vulnerability is a kernel-level issue in the Linux SMC (Socket Messaging Channel) subsystem that could lead to a NULL pointer dereference during socket teardown. It does not directly impact data confidentiality, integrity, or availability in a way that would violate GDPR or HIPAA requirements. However, if exploited, it could cause system instability or crashes, potentially disrupting services handling sensitive data.

Mitigation Strategies

Apply the latest Linux kernel security patches from your distribution vendor. If immediate patching is not possible, consider disabling SMC protocol usage in your network configuration or services until the patch is applied. Monitor system stability and network performance for signs of related issues.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80984. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart