Description
In the Linux kernel, the following vulnerability has been resolved:

net/smc: fix use-after-free in smc_rx_pipe_buf_release()

smc_rx_splice() hands RMB pages to a pipe and takes a socket reference
per entry so the smc_sock stays alive until the reader finishes. The
connection does not: a concurrent close runs smc_conn_free(), which
releases the receive buffer back to the link group pool.

smc_rx_pipe_buf_release() tests sk_state before taking the socket lock.
The state can change between the test and the lock, and
smc_rx_update_cons() then dereferences conn->rmb_desc and walks
conn->lgr, which smc_conn_free() has already released. On the
is_reg_err path smcr_buf_unuse() frees the descriptor outright, so
this is a use-after-free.

Take the socket lock first and test conn->freed instead.
smc_conn_free() sets that flag before releasing anything, and every
caller holds the socket lock. The two paths exclude each other: either
the pipe release runs first with everything valid, or it sees the flag
and skips the update.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free may corrupt kernel memory and enable local privilege escalation
Action: Immediate Patch
AI Analysis

Impact

The issue is a race condition in the Linux kernel's SMC networking module. When a socket is closed concurrently with the release of a pipe buffer, the driver can dereference memory that has already been freed. This use‑after‑free (CWE‑825) can corrupt kernel state and potentially allow a local attacker to execute arbitrary code with kernel privileges.

Affected Systems

Any Linux kernel build that includes the net/smc driver andc vulnerable. The vulnerability affects the kernel as a whole and is not tied to a specific hardware device; it is triggered by operations on the SMC network socket.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity. The EPSS score of less than 1 % suggests a low probability of real‑world exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require an attacker with local access to the affected kernel and the ability to manipulate the SMC socket state while data is being piped, which is not a typical remote attack scenario.

Generated by OpenCVE AI on September 21, 2026 at 02:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel version that contains the smc_rx_pipe_buf_release patch (e.g., upgrade to the latest stable release or apply the individual patch from the kernel repository).
  • If the SMC driver is not required, disable it in the kernel configuration or unload the module to reduce the attack surface.
  • For systems that cannot be upgraded immediately, apply any vendor‑supplied backported patch that incorporates this fix.

Generated by OpenCVE AI on September 21, 2026 at 02:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net/smc: fix use-after-free in smc_rx_pipe_buf_release() smc_rx_splice() hands RMB pages to a pipe and takes a socket reference per entry so the smc_sock stays alive until the reader finishes. The connection does not: a concurrent close runs smc_conn_free(), which releases the receive buffer back to the link group pool. smc_rx_pipe_buf_release() tests sk_state before taking the socket lock. The state can change between the test and the lock, and smc_rx_update_cons() then dereferences conn->rmb_desc and walks conn->lgr, which smc_conn_free() has already released. On the is_reg_err path smcr_buf_unuse() frees the descriptor outright, so this is a use-after-free. Take the socket lock first and test conn->freed instead. smc_conn_free() sets that flag before releasing anything, and every caller holds the socket lock. The two paths exclude each other: either the pipe release runs first with everything valid, or it sees the flag and skips the update.
Title net/smc: fix use-after-free in smc_rx_pipe_buf_release()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:59:25.672Z

Reserved: 2026-08-26T14:34:25.811Z

Link: CVE-2026-80982

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:04.667

Modified: 2026-09-14T13:18:52.947

Link: CVE-2026-80982

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:42Z

Links: CVE-2026-80982 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T02:30:08Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference