Impact
The vulnerability is a use‑after‑free in the Linux kernel’s SMC (Secure Monitor Call) subsystem. During the addition of an LLC link, the code keeps a pointer to a queue entry, frees the entry, and then later accesses that freed memory. This causes a crash or, if the reader continues, memory corruption and potential escalation.
Affected Systems
All Linux kernel builds before the commit that fixes this bug are affected. No specific version range is listed, but any kernel that does not contain the patch that removes the use‑after‑free in smc_llc_srv_add_link() is vulnerable. The CVE current and older kernels lacking the fix are considered at risk.
Risk and Exploitability
The indicates a critical severity. The EPSS score remains below 1%, and the vulnerability is not listed in CISA’s KEV catalog.MC framework; the likely attack vector is local, requiring the ability to initiate an SMC LLC link with specific parameters (e.g., max_recv_sge set to 1). An attacker with local kernel privileges could trigger the fault, leading to memory corruption and possible escalation. Because the flaw is not remotely reachable through a network interface, the immediate threat remains limited to trusted or compromised local contexts.
OpenCVE Enrichment