Impact
The flaw arises because three single‑bit flags—killed, freed, and out_of_sync—share one byte in the smc_connection structure. Each flag is updated independently without a common lock, causing read‑modify‑write operations that race between tasklet and process context code. When the race occurs, the kernel may store an invalid or stale value for one flag while leaving the others unchanged, resulting in inconsistent socket state. The flaw does not provide a direct path to privilege escalation or remote code execution. The CVSS score of 9.8 classifies this vulnerability as critical.
Affected Systems
All Linux kernel installations that have not incorporated the patch referenced by commit 2cb7a8d64b7e8ccdc69bbe48fe9c4eaa79c33aec are affected. The vulnerability resides in every distribution that ships with an unpatched kernel containing the shared‑byte implementation of the SMC protocol.
Risk and Exploitability
The CVSS score of 9.8 classifies this as a critical flaw that may allow serious impact if exploited. The EPSS of less than 1% indicates that, while the vulnerability is severe, actively malicious exploitation remains unlikely at present. The vulnerability is not listed in CISA’s KEV catalog, and no public exploits are known. The likely attack vector is sending crafted SMC packets that trigger the store race conditions, potentially causing kernel failure or denial of service. However, exploitation complexity is high, and misuse would require kernel‑level privilege or local access.
OpenCVE Enrichment