Description
In the Linux kernel, the following vulnerability has been resolved:

net/smc: release the internal TCP sock on IPPROTO_SMC socket creation failure

IPPROTO_SMC sockets create an internal TCP sock ("clcsock") from the
proto->init hook. When socket creation fails after proto->init has
run - e.g. a cgroup BPF program attached to BPF_CGROUP_INET_SOCK_CREATE
denies the socket - sk_common_release() only invokes sk_prot->destroy
if it is set, but neither smc_inet_prot nor smc_inet6_prot defines it,
and smc_destruct() returns early unless sk_state is SMC_CLOSED. As a
result, every failing socket(AF_INET, SOCK_STREAM, IPPROTO_SMC) call
leaks one tcp_sock, so an unprivileged task able to attach a deny-all
BPF_CGROUP_INET_SOCK_CREATE program to its own cgroup can grow kernel
memory unboundedly.

Add a .destroy hook to both protos that releases the clcsock via
smc_clcsock_release(). smc_sk_init() hashes the sock into the smc
hashinfo before the clcsock is created, and smc_diag dumps walk that
hash dereferencing smc->clcsock without taking clcsock_release_lock,
while sk_common_release() calls .destroy before .unhash. Unhash the
sock before releasing the clcsock, as __smc_release() does, so a
concurrent dump cannot observe the release; the second unhash in
sk_common_release() is a no-op.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Memory Leak / Denial of Service
Action: Patch
AI Analysis

Impact

The Linux kernel creates an internal TCP socket when an IPPROTO_SMC socket is opened. If the socket creation fails after the TCP socket has been allocated, that internal socket is not released because neither smc_inet_prot nor smc_inet6_prot defines a .destroy hook. The result is a memory leak of the TCP socket struct. By attaching an unprivileged BPF_CGROUP_INET_SOCK_CREATE program that denies socket creation to its own cgroup, an attacker can repeatedly attempt to create the failing socket and cause the kernel memory usage to grow arbitrarily, eventually leading to a denial‑of‑service event when the kernel runs out of memory.

Affected Systems

All Linux kernel releases before the commit that introduces the .destroy hook for smc_inet_prot and smc_inet6_prot are affected. This includes the kernels used by major distributions such as Ubuntu, Debian, CentOS, Fedora, Red Hat Enterprise Linux, and others that ship the kernel without the patch.

Risk and Exploitability

The EPSS score is <1%, indicating a very low probability that this vulnerability will be exploited in the wild. The vulnerability is not present in CISA’s KEV catalog and there are no publicly known exploit code or reports. The attack vector requires a local unprivileged user with the ability to attach a BPF program that denies socket creation to its cgroup. While feasible, the exploitation path is somewhat involved and the impact is limited to kernel memory exhaustion, making the practical risk moderate until a patch is applied.

Generated by OpenCVE AI on September 20, 2026 at 04:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the fix implementing a .destroy hook for IPPROTO_SMC sockets.
  • For workloads that may need IPPROTO_SMC sockets, avoid attaching deny‑all BPF_CGROUP_INET_SOCK_CREATE programs to the same cgroup or use separate cgroups.
  • Monitor kernel memory usage and kernel logs for abnormal growth of TCP socket structures, and be prepared to remediate or isolate affected containers if memory consumption spikes.

Generated by OpenCVE AI on September 20, 2026 at 04:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net/smc: release the internal TCP sock on IPPROTO_SMC socket creation failure IPPROTO_SMC sockets create an internal TCP sock ("clcsock") from the proto->init hook. When socket creation fails after proto->init has run - e.g. a cgroup BPF program attached to BPF_CGROUP_INET_SOCK_CREATE denies the socket - sk_common_release() only invokes sk_prot->destroy if it is set, but neither smc_inet_prot nor smc_inet6_prot defines it, and smc_destruct() returns early unless sk_state is SMC_CLOSED. As a result, every failing socket(AF_INET, SOCK_STREAM, IPPROTO_SMC) call leaks one tcp_sock, so an unprivileged task able to attach a deny-all BPF_CGROUP_INET_SOCK_CREATE program to its own cgroup can grow kernel memory unboundedly. Add a .destroy hook to both protos that releases the clcsock via smc_clcsock_release(). smc_sk_init() hashes the sock into the smc hashinfo before the clcsock is created, and smc_diag dumps walk that hash dereferencing smc->clcsock without taking clcsock_release_lock, while sk_common_release() calls .destroy before .unhash. Unhash the sock before releasing the clcsock, as __smc_release() does, so a concurrent dump cannot observe the release; the second unhash in sk_common_release() is a no-op.
Title net/smc: release the internal TCP sock on IPPROTO_SMC socket creation failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:05:48.269Z

Reserved: 2026-09-11T19:38:34.784Z

Link: CVE-2026-90065

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:16:55.327

Modified: 2026-09-17T17:16:55.327

Link: CVE-2026-90065

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:15:17Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime