From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F0F6C560ACC for ; Fri, 11 Sep 2026 19:48:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156110; cv=none; b=Sht+lPIuKA9B/piCF6BKGCLR4JcbMSEh4vKgY5IIBFalca0daxMC58rtfb853GQC70BjRWa3quIWeLYDd3lKPMO1O9DWl7Nal6QR6aYutm0SIbit7/xk1LKLsUDEWY6P9iNSlezSalcQJh0M+QjQRaM1LAQVXhsP/MF42l1Q/JY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156110; c=relaxed/simple; bh=P7fS+nc4V9PvH4lQFqngLNb7YS1g5MIgrC52VeAVne0=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=dGW1tqcXDPveTbgT98ytuLs+8pM8O3z6sdV/Yw4ukX7pdcjGrwI4P444UtkFS5o61JBfDWSqTc8eI+71+XqcnYQ/JFu2SlB793C4man4AL9ln67pUTtUhziH4JaXdu6c3BBXAvcXeX19rSEnOiZuNjM/Ln2sMmR1PaL0MoK7NCE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=NDfweWk0; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="NDfweWk0" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 5DAFC1F00898; Fri, 11 Sep 2026 19:48:13 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156093; bh=MnP5qyIaW3rG12Foe3L7mvs/np6lE0qK6Cd71ZN/rYs=; h=From:To:Cc:Subject:Date:Reply-To; b=NDfweWk0F8CF08X4pUXr/oNZOOe7t7ugOoOCx3lMI1ivrxeYHkvCvNxn/eB1TIjKB VWTSTTnka3Z4OAI6jk5NnxmfZmVPSleZb+wuZnEsHTfe0j5/fghFyceIWWPxXJqWqE blZKsmkAPf1VC6ooJSI/mNXZTSqzPFWIKsLviIX4= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80984: net/smc: do not dereference an unset send buffer on the SMC-D teardown path Date: Fri, 11 Sep 2026 21:41:30 +0200 Message-ID: <2026091147-CVE-2026-80984-b0ca@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3106; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=YFtMY7dqHLVZCR+dwvlbc5RJOZx1EQxqRi3GhZiS4Cw=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIu2325d/2mHxe4qz3uKgn1Gr8119X94tvll6b1XGg X8bpypmdcSyMAgyMciKKbJ82cZzdH/FIUUvQ9vTMHNYmUCGMHBxCsBEsnQZ5qk8YpnFOFl0nZf8 o7qYR68f2mct0maYXzHXJMlv39QpKtGtthUrf71vCVv4DAA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: net/smc: do not dereference an unset send buffer on the SMC-D teardown path smc_close_stream_wait() calls smc_tx_prepared_sends() from inside its sk_wait_event() condition, and sk_wait_event() evaluates that condition once with the socket lock released. smcd_buf_detach() clears conn->sndbuf_desc from smc_conn_kill() under lock_sock(), so a link group terminating while a socket waits there leaves the helper dereferencing NULL, faulting out of close(). SIOCOUTQ reads the field by hand, and smc_close_cancel_work() drops the lock across two cancel_*_sync() calls. Sample the pointer once in the helper, report nothing prepared while it is unset, and bound the ioctl the same way. The receive tasklet dereferences the field directly in smc_cdc_msg_recv_action(), not through this helper; 1/2 is what keeps it from running that late. The Linux kernel CVE team has assigned CVE-2026-80984 to this issue. Affected and fixed versions =========================== Issue introduced in 6.10 with commit ae2be35cbed2c8385e890147ea321a3fcc3ca5fa and fixed in 6.12.109 with commit e3fcff8d22a6c9540748846cd800443a643553a6 Issue introduced in 6.10 with commit ae2be35cbed2c8385e890147ea321a3fcc3ca5fa and fixed in 6.18.50 with commit f950e1b1f0aad334f9a9ee552c4dd5b794ebdd45 Issue introduced in 6.10 with commit ae2be35cbed2c8385e890147ea321a3fcc3ca5fa and fixed in 7.2.4 with commit f517cf02033801a28f98d86ca613a3533cf066b3 Issue introduced in 6.10 with commit ae2be35cbed2c8385e890147ea321a3fcc3ca5fa and fixed in 7.3-rc1 with commit b395dd319cea422239cb45b998fb38d7e373af87 Issue introduced in 6.6.66 with commit 21f6f41e82e59740e26e06e77bdf58dc7f6f08dd Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80984 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/smc/af_smc.c net/smc/smc_tx.h Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/e3fcff8d22a6c9540748846cd800443a643553a6 https://git.kernel.org/stable/c/f950e1b1f0aad334f9a9ee552c4dd5b794ebdd45 https://git.kernel.org/stable/c/f517cf02033801a28f98d86ca613a3533cf066b3 https://git.kernel.org/stable/c/b395dd319cea422239cb45b998fb38d7e373af87