Description
In the Linux kernel, the following vulnerability has been resolved:

net/smc: unregister the connection before draining the rx tasklet

smc_conn_free() calls smc_ism_unset_conn() only while the link group is
still on its device list, and never sets conn->killed.
smc_lgr_terminate_sched() unlinks the group immediately and defers killing
its connections to a work item, so a connection freed in that window keeps
its smcd->conn[] slot with both gates in smcd_handle_irq() open, and the
device can re-arm the receive tasklet after tasklet_kill() has returned. On
the DMB-nocopy path the ghost send buffer is freed right after that drain,
so the re-armed tasklet dereferences it.

Unregister unconditionally and drain before the detach at both teardown
sites, mirroring rmb_desc, which smc_buf_unuse() releases after the drain.
Clear conn->sndbuf_desc before freeing it as well, so a reader that samples
the pointer cannot get one that is already freed.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑ leading to kernel crash or memory corruption
Action: Apply patch
AI Analysis

Impact

The smc driver contains a race condition where a connection is freed while its receive tasklet remains armed. This race causes a dangling reference to a freed ghost send buffer, leading to a use‑after‑free that can corrupt kernel memory. The weakness is an Error Handled Incorrectly scenario (CWE‑825). If an attacker can trigger the fault, privilege escalation is possible.

Affected Systems

All Linux kernel implementations that include the smc driver. The vulnerability affects every distribution that ships the unpatched smc patch level is listed.

Risk and Exploitability

The assigned CVSS score of 7.8 indicates a moderately high severity. The EPSS score is <1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting the exploitation probability is uncertain but could be higher once a suitable trigger is inferred to be local or remote code execution through crafted network traffic to the smc interface, as the flaw involves kernel tasklet handling of incoming packets. Exploitation would require the attacker to trigger the race condition before the tasklet is drained, which could be achieved by sending specifically timed packets to the smc connection, though the exact method is not disclosed.

Generated by OpenCVE AI on September 21, 2026 at 02:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel update that includes the smc driver fix.
  • If an immediate kernel upgrade is not possible, disable services that establish smc connections or unload the smc kernel module until the patch is applied.
  • Monitor system logs for memory corruption or tasklet re‑arming anomalies, and reboot promptly if a kernel panic or suspicious activity occurs.

Generated by OpenCVE AI on September 21, 2026 at 02:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net/smc: unregister the connection before draining the rx tasklet smc_conn_free() calls smc_ism_unset_conn() only while the link group is still on its device list, and never sets conn->killed. smc_lgr_terminate_sched() unlinks the group immediately and defers killing its connections to a work item, so a connection freed in that window keeps its smcd->conn[] slot with both gates in smcd_handle_irq() open, and the device can re-arm the receive tasklet after tasklet_kill() has returned. On the DMB-nocopy path the ghost send buffer is freed right after that drain, so the re-armed tasklet dereferences it. Unregister unconditionally and drain before the detach at both teardown sites, mirroring rmb_desc, which smc_buf_unuse() releases after the drain. Clear conn->sndbuf_desc before freeing it as well, so a reader that samples the pointer cannot get one that is already freed.
Title net/smc: unregister the connection before draining the rx tasklet
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:59:24.610Z

Reserved: 2026-08-26T14:34:25.811Z

Link: CVE-2026-80979

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:04.277

Modified: 2026-09-14T13:18:52.803

Link: CVE-2026-80979

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:42:40Z

Links: CVE-2026-80979 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T02:30:08Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference