Description
In the Linux kernel, the following vulnerability has been resolved:

net/smc: stop killed, freed and out_of_sync sharing a byte

The three connection state flags are single-bit bitfields, so they occupy
one byte of struct smc_connection and every store to one is a
read-modify-write of the other two:

u8 killed : 1;
u8 freed : 1;
u8 out_of_sync : 1;

They are not written under a common lock. smc_cdc_msg_validate() sets
out_of_sync from the receive tasklet, while smc_conn_kill() sets killed
from process context under lock_sock(), and the receive path does not defer
to the backlog when the socket is owned -- smc_cdc_msg_recv() takes only
bh_lock_sock().

Give each flag its own byte so a store no longer touches its neighbours.
All readers test them as booleans and are unchanged. struct smc_connection
grows by two bytes.
Published: 2026-09-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Inconsistent socket state due to small‑byte race in SMC protocol
Action: Patch
AI Analysis

Impact

The flaw arises because three single‑bit flags—killed, freed, and out_of_sync—share one byte in the smc_connection structure. Each flag is updated independently without a common lock, causing read‑modify‑write operations that race between tasklet and process context code. When the race occurs, the kernel may store an invalid or stale value for one flag while leaving the others unchanged, resulting in inconsistent socket state. The flaw does not provide a direct path to privilege escalation or remote code execution. The CVSS score of 9.8 classifies this vulnerability as critical.

Affected Systems

All Linux kernel installations that have not incorporated the patch referenced by commit 2cb7a8d64b7e8ccdc69bbe48fe9c4eaa79c33aec are affected. The vulnerability resides in every distribution that ships with an unpatched kernel containing the shared‑byte implementation of the SMC protocol.

Risk and Exploitability

The CVSS score of 9.8 classifies this as a critical flaw that may allow serious impact if exploited. The EPSS of less than 1% indicates that, while the vulnerability is severe, actively malicious exploitation remains unlikely at present. The vulnerability is not listed in CISA’s KEV catalog, and no public exploits are known. The likely attack vector is sending crafted SMC packets that trigger the store race conditions, potentially causing kernel failure or denial of service. However, exploitation complexity is high, and misuse would require kernel‑level privilege or local access.

Generated by OpenCVE AI on September 21, 2026 at 02:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel release that includes the CVE‑2026‑80980 fix (CWE‑366).
  • Update the distribution kernel to a patched version according to the vendor’s security policy.
  • Restart any affected SMC services and monitor kernel logs for anomalous socket behavior.

Generated by OpenCVE AI on September 21, 2026 at 02:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-366
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net/smc: stop killed, freed and out_of_sync sharing a byte The three connection state flags are single-bit bitfields, so they occupy one byte of struct smc_connection and every store to one is a read-modify-write of the other two: u8 killed : 1; u8 freed : 1; u8 out_of_sync : 1; They are not written under a common lock. smc_cdc_msg_validate() sets out_of_sync from the receive tasklet, while smc_conn_kill() sets killed from process context under lock_sock(), and the receive path does not defer to the backlog when the socket is owned -- smc_cdc_msg_recv() takes only bh_lock_sock(). Give each flag its own byte so a store no longer touches its neighbours. All readers test them as booleans and are unchanged. struct smc_connection grows by two bytes.
Title net/smc: stop killed, freed and out_of_sync sharing a byte
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:28:46.582Z

Reserved: 2026-08-26T14:34:25.811Z

Link: CVE-2026-80980

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:04.407

Modified: 2026-09-13T07:17:04.887

Link: CVE-2026-80980

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:40Z

Links: CVE-2026-80980 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T02:30:08Z

Weaknesses
  • CWE-366

    Race Condition within a Thread