Impact
The Linux kernel’s net/smc driver mis‑handles oversized SMC a 44‑byte union into a buffer that is too small for the message. The driver then processes the excess rkeys, deleting legitimate remote tokens and installing corrupted ones. This out‑of‑bounds read (CWE‑125) can corrupt the SMC link state and eventually exhaust resources, leading to a denial of network service.
Affected Systems
All Linux kernel builds that include the net/smc driver before the commit 0d6f80be8ac5886842640d6526abf3f9a215be75 (or an equivalent patch) are affected. The vulnerability is not limited to a specific distribution or kernel release and applies to any host running a kernel version that has not applied this patch.
Risk and Exploitability
The CVSS score of 8.2 classifies this as a high‑severity vulnerability, while the EPSS score of less than 1% indicates a low likelihood of exploitation today. The likely attack vector is remote: an adversary who can send crafted SMC‑Rv2 LLC traffic over a network link to a target Linux system could trigger the out‑of‑bounds read and delete valid rtokens, potentially exhausting resources or causing a full denial of service on the SMC link.
OpenCVE Enrichment