Impact
The bug resides in the Linux kernel’s network SMC switch routine, where an early exit path fails to decrement a socket reference that had been incremented prior to a lock drop. This mismatch allows the socket reference counter to increase permanently, leaving the associated socket and its buffers alive indefinitely. Over time, accumulated leaked sockets consume memory and prevent the associated network namespace from being torn down, representing a classic resource‑leak weakness (CWE‑911). The impact is limited to the kernel space; it does not provide direct code execution or privilege escalation, but can degrade system stability as resources are exhausted.
Affected Systems
All Linux kernel builds that ship the network SMC (smc) module without the referenced fix are affected. This includes any distribution running a kernel version prior to the patch commit 09d7a9e1, which introduces proper reference‑count handling in smc_switch_conns(). Users should check the kernel version on their systems and verify that the patch is present or plan an upgrade.
Risk and Exploitability
The CVSS score of 4.7 reflects low severity, and the EPSS score of less than 1% indicates a small likelihood of exploitation. Based on the description, the flaw requires a local or privileged kernel context, typically triggered during link failover events handled by the smc module. Remote or unprivileged exploitation is unlikely, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation.
OpenCVE Enrichment
Debian DSA