0.0
NA
CVE-2026-64541
net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket
Description

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket smc_cdc_rx_handler() looks up the connection by token under the link group's conns_lock, drops the lock, and then dereferences conn and the smc_sock derived from it, ending in sock_hold(&smc->sk) inside smc_cdc_msg_recv(). No reference is held across the lock release. The only reference pinning the socket while the connection is discoverable in the link group is taken in smc_lgr_register_conn() (sock_hold) and dropped in __smc_lgr_unregister_conn() (sock_put), both under conns_lock. Once the handler drops conns_lock, a concurrent close() -> smc_release() -> smc_conn_free() -> smc_lgr_unregister_conn() can drop that reference and free the smc_sock, so the handler's later sock_hold() runs on freed memory: WARNING: lib/refcount.c:25 at refcount_warn_saturate Workqueue: rxe_wq do_work refcount_warn_saturate (lib/refcount.c:25) smc_cdc_msg_recv (net/smc/smc_cdc.c:430) smc_cdc_rx_handler (net/smc/smc_cdc.c:502) smc_wr_rx_tasklet_fn (net/smc/smc_wr.c:445) tasklet_action_common (kernel/softirq.c:938) handle_softirqs (kernel/softirq.c:622) Kernel panic - not syncing: panic_on_warn set Only SMC-R is affected. The SMC-D receive tasklet is stopped by tasklet_kill(&conn->rx_tsklet) in smc_conn_free() before the connection is unregistered, so it cannot run concurrently with the free. Take the socket reference while still holding conns_lock, so the registration reference can no longer be the last one, and drop it once the handler is done.

INFO

Published Date :

July 27, 2026, 9:17 p.m.

Last Modified :

July 27, 2026, 9:17 p.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-64541 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

No affected product recoded yet

Solution
Fix use-after-free in smc_cdc_rx_handler by pinning the socket correctly.
  • Apply the provided kernel patch.
  • Ensure socket references are held.
  • Pin socket before dereferencing.
  • Drop reference after handler completion.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-64541 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-64541 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-64541 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-64541 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Jul. 27, 2026

    Action Type Old Value New Value
    Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': 'd7b0e37c1ac152905b18a5b9506179091a35b0b6', 'lessThan': '8de4f665d0febfb92803dece377791a563fc7041', 'versionType': 'git'}, {'status': 'affected', 'version': 'd7b0e37c1ac152905b18a5b9506179091a35b0b6', 'lessThan': '8145b432136285e01091815b48ceb2dae261f262', 'versionType': 'git'}, {'status': 'affected', 'version': 'd7b0e37c1ac152905b18a5b9506179091a35b0b6', 'lessThan': '1951bffbc6493ec34cff3956b29d4bc6606904a6', 'versionType': 'git'}, {'status': 'affected', 'version': 'd7b0e37c1ac152905b18a5b9506179091a35b0b6', 'lessThan': '647b19e5cc145a2f1f685ae8ff3805a17356888c', 'versionType': 'git'}, {'status': 'affected', 'version': 'd7b0e37c1ac152905b18a5b9506179091a35b0b6', 'lessThan': '472e9d7c0d5b03be3ff91ff941f57da822b031bc', 'versionType': 'git'}, {'status': 'affected', 'version': 'd7b0e37c1ac152905b18a5b9506179091a35b0b6', 'lessThan': '3bfb96d9bc6a7ed0b99c7db329cc2e22a28d84bb', 'versionType': 'git'}, {'status': 'affected', 'version': 'd7b0e37c1ac152905b18a5b9506179091a35b0b6', 'lessThan': 'ce5aa8084329351086894aa34d77e40301d5bd3d', 'versionType': 'git'}, {'status': 'affected', 'version': 'd7b0e37c1ac152905b18a5b9506179091a35b0b6', 'lessThan': '9d160b35cc34a2ba8229d07651468a7848325135', 'versionType': 'git'}], 'programFiles': ['net/smc/smc_cdc.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '4.18'}, {'status': 'unaffected', 'version': '0', 'lessThan': '4.18', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.261', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.212', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc3', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/smc/smc_cdc.c'], 'defaultStatus': 'affected'}]
    Added Description In the Linux kernel, the following vulnerability has been resolved: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket smc_cdc_rx_handler() looks up the connection by token under the link group's conns_lock, drops the lock, and then dereferences conn and the smc_sock derived from it, ending in sock_hold(&smc->sk) inside smc_cdc_msg_recv(). No reference is held across the lock release. The only reference pinning the socket while the connection is discoverable in the link group is taken in smc_lgr_register_conn() (sock_hold) and dropped in __smc_lgr_unregister_conn() (sock_put), both under conns_lock. Once the handler drops conns_lock, a concurrent close() -> smc_release() -> smc_conn_free() -> smc_lgr_unregister_conn() can drop that reference and free the smc_sock, so the handler's later sock_hold() runs on freed memory: WARNING: lib/refcount.c:25 at refcount_warn_saturate Workqueue: rxe_wq do_work refcount_warn_saturate (lib/refcount.c:25) smc_cdc_msg_recv (net/smc/smc_cdc.c:430) smc_cdc_rx_handler (net/smc/smc_cdc.c:502) smc_wr_rx_tasklet_fn (net/smc/smc_wr.c:445) tasklet_action_common (kernel/softirq.c:938) handle_softirqs (kernel/softirq.c:622) Kernel panic - not syncing: panic_on_warn set Only SMC-R is affected. The SMC-D receive tasklet is stopped by tasklet_kill(&conn->rx_tsklet) in smc_conn_free() before the connection is unregistered, so it cannot run concurrently with the free. Take the socket reference while still holding conns_lock, so the registration reference can no longer be the last one, and drop it once the handler is done.
    Added Reference https://git.kernel.org/stable/c/1951bffbc6493ec34cff3956b29d4bc6606904a6
    Added Reference https://git.kernel.org/stable/c/3bfb96d9bc6a7ed0b99c7db329cc2e22a28d84bb
    Added Reference https://git.kernel.org/stable/c/472e9d7c0d5b03be3ff91ff941f57da822b031bc
    Added Reference https://git.kernel.org/stable/c/647b19e5cc145a2f1f685ae8ff3805a17356888c
    Added Reference https://git.kernel.org/stable/c/8145b432136285e01091815b48ceb2dae261f262
    Added Reference https://git.kernel.org/stable/c/8de4f665d0febfb92803dece377791a563fc7041
    Added Reference https://git.kernel.org/stable/c/9d160b35cc34a2ba8229d07651468a7848325135
    Added Reference https://git.kernel.org/stable/c/ce5aa8084329351086894aa34d77e40301d5bd3d
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.