Impact
The smc driver contains a race condition where a connection is freed while its receive tasklet remains armed. This race causes a dangling reference to a freed ghost send buffer, leading to a use‑after‑free that can corrupt kernel memory. The weakness is an Error Handled Incorrectly scenario (CWE‑825). If an attacker can trigger the fault, privilege escalation is possible.
Affected Systems
All Linux kernel implementations that include the smc driver. The vulnerability affects every distribution that ships the unpatched smc patch level is listed.
Risk and Exploitability
The assigned CVSS score of 7.8 indicates a moderately high severity. The EPSS score is <1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting the exploitation probability is uncertain but could be higher once a suitable trigger is inferred to be local or remote code execution through crafted network traffic to the smc interface, as the flaw involves kernel tasklet handling of incoming packets. Exploitation would require the attacker to trigger the race condition before the tasklet is drained, which could be achieved by sending specifically timed packets to the smc connection, though the exact method is not disclosed.
OpenCVE Enrichment
Debian DSA