CVE-2026-64541 is a vulnerability in Linux Kernel
Published on July 27, 2026
net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket
In the Linux kernel, the following vulnerability has been resolved:
net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket
smc_cdc_rx_handler() looks up the connection by token under the link
group's conns_lock, drops the lock, and then dereferences conn and the
smc_sock derived from it, ending in sock_hold(&smc->sk) inside
smc_cdc_msg_recv(). No reference is held across the lock release.
The only reference pinning the socket while the connection is
discoverable in the link group is taken in smc_lgr_register_conn()
(sock_hold) and dropped in __smc_lgr_unregister_conn() (sock_put), both
under conns_lock. Once the handler drops conns_lock, a concurrent
close() -> smc_release() -> smc_conn_free() -> smc_lgr_unregister_conn()
can drop that reference and free the smc_sock, so the handler's later
sock_hold() runs on freed memory:
WARNING: lib/refcount.c:25 at refcount_warn_saturate
Workqueue: rxe_wq do_work
refcount_warn_saturate (lib/refcount.c:25)
smc_cdc_msg_recv (net/smc/smc_cdc.c:430)
smc_cdc_rx_handler (net/smc/smc_cdc.c:502)
smc_wr_rx_tasklet_fn (net/smc/smc_wr.c:445)
tasklet_action_common (kernel/softirq.c:938)
handle_softirqs (kernel/softirq.c:622)
Kernel panic - not syncing: panic_on_warn set
Only SMC-R is affected. The SMC-D receive tasklet is stopped by
tasklet_kill(&conn->rx_tsklet) in smc_conn_free() before the connection
is unregistered, so it cannot run concurrently with the free.
Take the socket reference while still holding conns_lock, so the
registration reference can no longer be the last one, and drop it once
the handler is done.
Products Associated with CVE-2026-64541
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version d7b0e37c1ac152905b18a5b9506179091a35b0b6 and below 8de4f665d0febfb92803dece377791a563fc7041 is affected.
- Version d7b0e37c1ac152905b18a5b9506179091a35b0b6 and below 8145b432136285e01091815b48ceb2dae261f262 is affected.
- Version d7b0e37c1ac152905b18a5b9506179091a35b0b6 and below 1951bffbc6493ec34cff3956b29d4bc6606904a6 is affected.
- Version d7b0e37c1ac152905b18a5b9506179091a35b0b6 and below 647b19e5cc145a2f1f685ae8ff3805a17356888c is affected.
- Version d7b0e37c1ac152905b18a5b9506179091a35b0b6 and below 472e9d7c0d5b03be3ff91ff941f57da822b031bc is affected.
- Version d7b0e37c1ac152905b18a5b9506179091a35b0b6 and below 3bfb96d9bc6a7ed0b99c7db329cc2e22a28d84bb is affected.
- Version d7b0e37c1ac152905b18a5b9506179091a35b0b6 and below ce5aa8084329351086894aa34d77e40301d5bd3d is affected.
- Version d7b0e37c1ac152905b18a5b9506179091a35b0b6 and below 9d160b35cc34a2ba8229d07651468a7848325135 is affected.
- Version 4.18 is affected.
- Before 4.18 is unaffected.
- Version 5.10.261, <= 5.10.* is unaffected.
- Version 5.15.212, <= 5.15.* is unaffected.
- Version 6.1.178, <= 6.1.* is unaffected.
- Version 6.6.145, <= 6.6.* is unaffected.
- Version 6.12.97, <= 6.12.* is unaffected.
- Version 6.18.40, <= 6.18.* is unaffected.
- Version 7.1.5, <= 7.1.* is unaffected.
- Version 7.2-rc3, <= * is unaffected.