CVE-2026-80985
Received Received - Intake

Buffer Overflow in Linux Kernel SMC-Rv2 Implementation

Vulnerability report for CVE-2026-80985, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-13

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry smc_llc_rmt_delete_rkey() and smc_llc_save_add_link_rkeys() read the part of a v2 message that does not fit into the 44-byte union smc_llc_msg, and both bound themselves by the size of the buffer it landed in, not by what arrived. On a link with a shared v2 receive buffer a 44-byte DELETE_RKEY_V2 declaring 255 rkeys reaches rkey[9..254] in whatever an earlier message left in lgr->wr_rx_buf_v2, and passes each of them to smc_rtoken_delete(). One of those 255 matched a registered rtoken and deleted it. An ADD_LINK on such a link installs up to 255 rtokens from the same bytes. Copy the tail into the queue entry, so its length is the length of the message that arrived, and declare the rkeys that fit inline as a member of the union instead of reaching them through a cast. The same DELETE_RKEY_V2 now processes the 9 rkeys it carries. The copy is limited to the longest tail the two functions can read, so the peer does not pick the size of the entry. The bound the previous patch placed on links without a shared v2 receive buffer is no longer needed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-13
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves improper handling of oversized SMC-Rv2 LLC messages. Functions smc_llc_rmt_delete_rkey() and smc_llc_save_add_link_rkeys() incorrectly read beyond the allocated buffer size, allowing an attacker to manipulate memory by sending a malformed message with 255 rkeys. This could lead to unauthorized deletion or installation of rtokens, potentially disrupting network communication or enabling further attacks.

Detection Guidance

This vulnerability is specific to the Linux kernel's SMC (Socket Direct) implementation and requires kernel-level inspection. Detection involves checking kernel logs for SMC-related errors or examining network traffic for malformed SMC-Rv2 messages. No direct commands are provided in the context, but monitoring for SMC errors in dmesg or kernel logs may help identify exploitation attempts.

Impact Analysis

If you use a Linux system with SMC-Rv2 enabled, this vulnerability could allow an attacker on the same network to disrupt network connections, delete valid tokens, or inject malicious tokens. This might cause service outages, unauthorized access, or data leaks depending on the system's configuration and usage.

Compliance Impact

This vulnerability affects compliance with standards and regulations like GDPR and HIPAA by potentially enabling unauthorized access to sensitive data. The flaw allows deletion or manipulation of registered tokens, which could lead to data exposure or integrity issues in systems handling protected information.

Mitigation Strategies

Update the Linux kernel to the latest patched version to resolve this vulnerability. Monitor vendor advisories for kernel updates addressing CVE-2026-80985.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80985. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart