Description
In the Linux kernel, the following vulnerability has been resolved:

net/smc: fix socket refcount leak in smc_switch_conns()

smc_switch_conns() takes a reference on the SMC socket before dropping
lgr->conns_lock, so the connection stays alive while the CDC slot is
fetched:

sock_hold(&smc->sk);
read_unlock_bh(&lgr->conns_lock);
/* pre-fetch buffer outside of send_lock, might sleep */
rc = smc_cdc_get_free_slot(conn, to_lnk, &wr_buf, NULL, &pend);
if (rc)
goto err_out;

The err_out label only drops the wr_tx link reference, so this early exit
returns without the matching sock_put(). The second error exit is not
affected, because sock_put() has already run by then.

A leaked sk_refcnt means the smc_sock is never destroyed. Its send and
receive buffers stay allocated, and for a user socket the reference held
on the network namespace is never released, so the netns can no longer be
torn down.

smc_cdc_get_free_slot() fails when the target link goes down or when the
connection has been killed while the switch is in progress. Both are
reachable during the link failover this function implements, so the leak
is triggered by the same hardware events that make smc_switch_conns() run
in the first place.

Restructure so there is a single sock_put() covering both outcomes,
instead of adding a second one to the error path.
Published: 2026-09-11
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Socket reference leak causing delayed network namespace teardown and potential resource exhaustion
Action: Apply kernel patch
AI Analysis

Impact

The bug resides in the Linux kernel’s network SMC switch routine, where an early exit path fails to decrement a socket reference that had been incremented prior to a lock drop. This mismatch allows the socket reference counter to increase permanently, leaving the associated socket and its buffers alive indefinitely. Over time, accumulated leaked sockets consume memory and prevent the associated network namespace from being torn down, representing a classic resource‑leak weakness (CWE‑911). The impact is limited to the kernel space; it does not provide direct code execution or privilege escalation, but can degrade system stability as resources are exhausted.

Affected Systems

All Linux kernel builds that ship the network SMC (smc) module without the referenced fix are affected. This includes any distribution running a kernel version prior to the patch commit 09d7a9e1, which introduces proper reference‑count handling in smc_switch_conns(). Users should check the kernel version on their systems and verify that the patch is present or plan an upgrade.

Risk and Exploitability

The CVSS score of 4.7 reflects low severity, and the EPSS score of less than 1% indicates a small likelihood of exploitation. Based on the description, the flaw requires a local or privileged kernel context, typically triggered during link failover events handled by the smc module. Remote or unprivileged exploitation is unlikely, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation.

Generated by OpenCVE AI on September 21, 2026 at 02:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the smc_switch_conns() fix to correct the reference‑count logic
  • If an immediate patch is unavailable, disable the SMC feature or USB CDC mode that uses it until the bug is resolved
  • Restart networking or reboot after updating or disabling the feature to refresh state
  • Monitor kernel logs and system memory usage for signs of unreleased sockets or namespace resources

Generated by OpenCVE AI on September 21, 2026 at 02:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-911
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net/smc: fix socket refcount leak in smc_switch_conns() smc_switch_conns() takes a reference on the SMC socket before dropping lgr->conns_lock, so the connection stays alive while the CDC slot is fetched: sock_hold(&smc->sk); read_unlock_bh(&lgr->conns_lock); /* pre-fetch buffer outside of send_lock, might sleep */ rc = smc_cdc_get_free_slot(conn, to_lnk, &wr_buf, NULL, &pend); if (rc) goto err_out; The err_out label only drops the wr_tx link reference, so this early exit returns without the matching sock_put(). The second error exit is not affected, because sock_put() has already run by then. A leaked sk_refcnt means the smc_sock is never destroyed. Its send and receive buffers stay allocated, and for a user socket the reference held on the network namespace is never released, so the netns can no longer be torn down. smc_cdc_get_free_slot() fails when the target link goes down or when the connection has been killed while the switch is in progress. Both are reachable during the link failover this function implements, so the leak is triggered by the same hardware events that make smc_switch_conns() run in the first place. Restructure so there is a single sock_put() covering both outcomes, instead of adding a second one to the error path.
Title net/smc: fix socket refcount leak in smc_switch_conns()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:59:26.742Z

Reserved: 2026-08-26T14:34:25.811Z

Link: CVE-2026-80983

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:04.787

Modified: 2026-09-14T13:18:53.090

Link: CVE-2026-80983

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:42Z

Links: CVE-2026-80983 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T02:30:08Z

Weaknesses
  • CWE-911

    Improper Update of Reference Count