Impact
The issue is a race condition in the Linux kernel's SMC networking module. When a socket is closed concurrently with the release of a pipe buffer, the driver can dereference memory that has already been freed. This use‑after‑free (CWE‑825) can corrupt kernel state and potentially allow a local attacker to execute arbitrary code with kernel privileges.
Affected Systems
Any Linux kernel build that includes the net/smc driver andc vulnerable. The vulnerability affects the kernel as a whole and is not tied to a specific hardware device; it is triggered by operations on the SMC network socket.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score of less than 1 % suggests a low probability of real‑world exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require an attacker with local access to the affected kernel and the ability to manipulate the SMC socket state while data is being piped, which is not a typical remote attack scenario.
OpenCVE Enrichment
Debian DSA