Description
In the Linux kernel, the following vulnerability has been resolved:

net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry

smc_llc_rmt_delete_rkey() and smc_llc_save_add_link_rkeys() read the part
of a v2 message that does not fit into the 44-byte union smc_llc_msg, and
both bound themselves by the size of the buffer it landed in, not by what
arrived. On a link with a shared v2 receive buffer a 44-byte
DELETE_RKEY_V2 declaring 255 rkeys reaches rkey[9..254] in whatever an
earlier message left in lgr->wr_rx_buf_v2, and passes each of them to
smc_rtoken_delete(). One of those 255 matched a registered rtoken and
deleted it. An ADD_LINK on such a link installs up to 255 rtokens from
the same bytes.

Copy the tail into the queue entry, so its length is the length of the
message that arrived, and declare the rkeys that fit inline as a member of
the union instead of reaching them through a cast. The same
DELETE_RKEY_V2 now processes the 9 rkeys it carries. The copy is limited
to the longest tail the two functions can read, so the peer does not pick
the size of the entry.

The bound the previous patch placed on links without a shared v2 receive
buffer is no longer needed.
Published: 2026-09-11
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The Linux kernel’s net/smc driver mis‑handles oversized SMC a 44‑byte union into a buffer that is too small for the message. The driver then processes the excess rkeys, deleting legitimate remote tokens and installing corrupted ones. This out‑of‑bounds read (CWE‑125) can corrupt the SMC link state and eventually exhaust resources, leading to a denial of network service.

Affected Systems

All Linux kernel builds that include the net/smc driver before the commit 0d6f80be8ac5886842640d6526abf3f9a215be75 (or an equivalent patch) are affected. The vulnerability is not limited to a specific distribution or kernel release and applies to any host running a kernel version that has not applied this patch.

Risk and Exploitability

The CVSS score of 8.2 classifies this as a high‑severity vulnerability, while the EPSS score of less than 1% indicates a low likelihood of exploitation today. The likely attack vector is remote: an adversary who can send crafted SMC‑Rv2 LLC traffic over a network link to a target Linux system could trigger the out‑of‑bounds read and delete valid rtokens, potentially exhausting resources or causing a full denial of service on the SMC link.

Generated by OpenCVE AI on September 21, 2026 at 02:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the commit 0d6f80be8ac5886842640d6526abf3f9a215be75.
  • If an immediate kernel upgrade is not possible, cherry‑pick or apply the upstream patch to the current kernel source and rebuild the kernel.
  • If SMC‑Rv2 functionality is not required, smc module or configuring the device to avoid using the smc driver.

Generated by OpenCVE AI on September 21, 2026 at 02:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:H'}

cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry smc_llc_rmt_delete_rkey() and smc_llc_save_add_link_rkeys() read the part of a v2 message that does not fit into the 44-byte union smc_llc_msg, and both bound themselves by the size of the buffer it landed in, not by what arrived. On a link with a shared v2 receive buffer a 44-byte DELETE_RKEY_V2 declaring 255 rkeys reaches rkey[9..254] in whatever an earlier message left in lgr->wr_rx_buf_v2, and passes each of them to smc_rtoken_delete(). One of those 255 matched a registered rtoken and deleted it. An ADD_LINK on such a link installs up to 255 rtokens from the same bytes. Copy the tail into the queue entry, so its length is the length of the message that arrived, and declare the rkeys that fit inline as a member of the union instead of reaching them through a cast. The same DELETE_RKEY_V2 now processes the 9 rkeys it carries. The copy is limited to the longest tail the two functions can read, so the peer does not pick the size of the entry. The bound the previous patch placed on links without a shared v2 receive buffer is no longer needed.
Title net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:28:50.166Z

Reserved: 2026-08-26T14:34:25.811Z

Link: CVE-2026-80985

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:05.050

Modified: 2026-09-13T07:17:05.290

Link: CVE-2026-80985

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:44Z

Links: CVE-2026-80985 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T02:15:08Z

Weaknesses