Description
In the Linux kernel, the following vulnerability has been resolved:

net/smc: free pending qentry in smc_llc_flow_stop() before memset

smc_llc_flow_stop() resets a flow struct with a blind memset:

spin_lock_bh(&lgr->llc_flow_lock);
memset(flow, 0, sizeof(*flow));
flow->type = SMC_LLC_FLOW_NONE;
spin_unlock_bh(&lgr->llc_flow_lock);

If flow->qentry is non-NULL at this point the pointer is overwritten without the
allocation being freed, leaking one kmalloc object.

A late-arriving duplicate CONFIRM_LINK or ADD_LINK_CONT message can set
flow->qentry after the legitimate message has been consumed by the waiter via
smc_llc_flow_qentry_clr() (which NULLs the pointer but leaves flow->type
non-zero) but before the flow completes and smc_llc_flow_stop() runs. In that
window the duplicate is stashed into flow->qentry, and then lost when
smc_llc_flow_stop() zeros the struct.

Call smc_llc_flow_qentry_del() inside the lock before the memset.
smc_llc_flow_qentry_del() already checks flow->qentry before freeing, so the
normal case where no entry is pending is a no-op.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Memory Leak Leading To Resource Exhaustion
Action: Patch Immediately
AI Analysis

Impact

The vulnerability exists in the Linux kernel's smc module where the smc_llc_flow_stop function zeros a flow structure while the flow->qentry pointer still references an allocated object. That pointer is overwritten before any free occurs, causing a single kernel memory object to leak. The defect is a form of improper memory management and can allow an attacker to accumulate leaks over time, potentially exhausting kernel memory and degrading system stability.

Affected Systems

Any Linux kernel version that contains the smc subsystem before the applied patch is subject to this flaw. The CNA data does not list specific product versions, but the kernel commit references indicate that the issue was present in all earlier releases. Users running any distribution that has not updated past the commit that introduces smc_llc_flow_qentry_del prior to the memset are affected.

Risk and Exploitability

The EPSS score is below 1%, and the vulnerability is not currently listed in the CISA KEV catalog, suggesting a low likelihood of active exploitation. However, the weakness can be triggered by a duplicate CONFIRM_LINK or ADD_LINK_CONT message sent over the network to the smc interface, which would allow a remote adversary to repeatedly cause memory leaks. While the flaw does not grant code execution, repeated exploitation could lead to a denial‑of‑service scenario through kernel memory exhaustion. Monitoring network traffic for anomalous smc packets and applying the patch are the recommended mitigations.

Generated by OpenCVE AI on September 18, 2026 at 22:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a release that incorporates the smc_llc_flow_qentry_del fix (for example, apply the commit 5ff429dd6725fa6c1e17a4ed0be8ab675f67a98b).
  • Recompile or reinstall the kernel if a prebuilt image is not available, ensuring the smc code is built with the patched function.
  • Reboot the system to activate the new kernel and verify that the memory leak no longer occurs.

Generated by OpenCVE AI on September 18, 2026 at 22:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net/smc: free pending qentry in smc_llc_flow_stop() before memset smc_llc_flow_stop() resets a flow struct with a blind memset: spin_lock_bh(&lgr->llc_flow_lock); memset(flow, 0, sizeof(*flow)); flow->type = SMC_LLC_FLOW_NONE; spin_unlock_bh(&lgr->llc_flow_lock); If flow->qentry is non-NULL at this point the pointer is overwritten without the allocation being freed, leaking one kmalloc object. A late-arriving duplicate CONFIRM_LINK or ADD_LINK_CONT message can set flow->qentry after the legitimate message has been consumed by the waiter via smc_llc_flow_qentry_clr() (which NULLs the pointer but leaves flow->type non-zero) but before the flow completes and smc_llc_flow_stop() runs. In that window the duplicate is stashed into flow->qentry, and then lost when smc_llc_flow_stop() zeros the struct. Call smc_llc_flow_qentry_del() inside the lock before the memset. smc_llc_flow_qentry_del() already checks flow->qentry before freeing, so the normal case where no entry is pending is a no-op.
Title net/smc: free pending qentry in smc_llc_flow_stop() before memset
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:16.157Z

Reserved: 2026-09-11T19:38:34.787Z

Link: CVE-2026-90107

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:02.570

Modified: 2026-09-17T17:17:02.570

Link: CVE-2026-90107

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T22:45:15Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime