๐Ÿ” CVE Alert

CVE-2026-80984

UNKNOWN 0.0

net/smc: do not dereference an unset send buffer on the SMC-D teardown path

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: net/smc: do not dereference an unset send buffer on the SMC-D teardown path smc_close_stream_wait() calls smc_tx_prepared_sends() from inside its sk_wait_event() condition, and sk_wait_event() evaluates that condition once with the socket lock released. smcd_buf_detach() clears conn->sndbuf_desc from smc_conn_kill() under lock_sock(), so a link group terminating while a socket waits there leaves the helper dereferencing NULL, faulting out of close(). SIOCOUTQ reads the field by hand, and smc_close_cancel_work() drops the lock across two cancel_*_sync() calls. Sample the pointer once in the helper, report nothing prepared while it is unset, and bound the ioctl the same way. The receive tasklet dereferences the field directly in smc_cdc_msg_recv_action(), not through this helper; 1/2 is what keeps it from running that late.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
21f6f41e82e59740e26e06e77bdf58dc7f6f08dd < ab26e12dd5d2f43d939fcf456933a816e81d2e51 ae2be35cbed2c8385e890147ea321a3fcc3ca5fa < e3fcff8d22a6c9540748846cd800443a643553a6 ae2be35cbed2c8385e890147ea321a3fcc3ca5fa < f950e1b1f0aad334f9a9ee552c4dd5b794ebdd45 ae2be35cbed2c8385e890147ea321a3fcc3ca5fa < f517cf02033801a28f98d86ca613a3533cf066b3 ae2be35cbed2c8385e890147ea321a3fcc3ca5fa < b395dd319cea422239cb45b998fb38d7e373af87 6.6.66 < 6.6.157
Linux / Linux
6.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/ab26e12dd5d2f43d939fcf456933a816e81d2e51 git.kernel.org: https://git.kernel.org/stable/c/e3fcff8d22a6c9540748846cd800443a643553a6 git.kernel.org: https://git.kernel.org/stable/c/f950e1b1f0aad334f9a9ee552c4dd5b794ebdd45 git.kernel.org: https://git.kernel.org/stable/c/f517cf02033801a28f98d86ca613a3533cf066b3 git.kernel.org: https://git.kernel.org/stable/c/b395dd319cea422239cb45b998fb38d7e373af87