Impact
The vulnerability occurs in the Linux kernel’s smc module when handling SMC‑R v2 link additions with a device having max_recv_sge set to 1. The smc_llc_save_add_link_rkeys function calculates an offset to a 72‑byte message, but the calculation points beyond the allocated 72 bytes. As a result, reading the num_rkeys field triggers a KASAN‑reported out‑of‑bounds read at offset 94. This represents a CWE‑787: Out‑of‑Bounds Read flaw that can lead to a kernel panic and system crash.
Affected Systems
All Linux kernel releases that include the unpatched smc module and support SMC‑R v2, such as kernel 7.2.0‑rc5 and earlier, are affected. Systems with the smc module loaded and the SMC interface exposed—regardless of distribution—are at risk. Any user space process that can provoke a link‑addition event on a peer device with max_recv_sge==1 will trigger the flaw.
Risk and Exploitability
The CVSS score of 9.8 signals a critical severity. EPSS less than 1% indicates current exploitation is unlikely. The vulnerability is not in CISA KEV. Exploitation would require triggering a link‑addition event, which an attacker might achieve over a network if the SMC interface is reachable, or locally if privileged code loads the smc module. The immediate risk is a system crash rather than privilege escalation, per the information supplied.
OpenCVE Enrichment