* CVE-2026-80985: net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry
@ 2026-09-11 19:41 Greg Kroah-Hartman
0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-11 19:41 UTC (permalink / raw)
To: linux-cve-announce; +Cc: Greg Kroah-Hartman
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry
smc_llc_rmt_delete_rkey() and smc_llc_save_add_link_rkeys() read the part
of a v2 message that does not fit into the 44-byte union smc_llc_msg, and
both bound themselves by the size of the buffer it landed in, not by what
arrived. On a link with a shared v2 receive buffer a 44-byte
DELETE_RKEY_V2 declaring 255 rkeys reaches rkey[9..254] in whatever an
earlier message left in lgr->wr_rx_buf_v2, and passes each of them to
smc_rtoken_delete(). One of those 255 matched a registered rtoken and
deleted it. An ADD_LINK on such a link installs up to 255 rtokens from
the same bytes.
Copy the tail into the queue entry, so its length is the length of the
message that arrived, and declare the rkeys that fit inline as a member of
the union instead of reaching them through a cast. The same
DELETE_RKEY_V2 now processes the 9 rkeys it carries. The copy is limited
to the longest tail the two functions can read, so the peer does not pick
the size of the entry.
The bound the previous patch placed on links without a shared v2 receive
buffer is no longer needed.
The Linux kernel CVE team has assigned CVE-2026-80985 to this issue.
Affected and fixed versions
===========================
Issue introduced in 6.14 with commit 27ef6a9981fe74191849966a6d5e0400a4008ab8 and fixed in 6.18.50 with commit edf30d65e3ac52f886f7d87b1a7449742e79157d
Issue introduced in 6.14 with commit 27ef6a9981fe74191849966a6d5e0400a4008ab8 and fixed in 7.2.4 with commit 0d6f80be8ac5886842640d6526abf3f9a215be75
Issue introduced in 6.14 with commit 27ef6a9981fe74191849966a6d5e0400a4008ab8 and fixed in 7.3-rc1 with commit 8d3c1ab82c11d4fadebf817a825fd221b3e197ea
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-80985
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
net/smc/smc_llc.c
net/smc/smc_wr.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/edf30d65e3ac52f886f7d87b1a7449742e79157d
https://git.kernel.org/stable/c/0d6f80be8ac5886842640d6526abf3f9a215be75
https://git.kernel.org/stable/c/8d3c1ab82c11d4fadebf817a825fd221b3e197ea
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-09-11 19:48 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-11 19:41 CVE-2026-80985: net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry Greg Kroah-Hartman
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.