๐Ÿ” CVE Alert

CVE-2026-90108

UNKNOWN 0.0

net/smc: free stashed qentry before overwrite in REQ_ADD_LINK to ADD_LINK transition

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: net/smc: free stashed qentry before overwrite in REQ_ADD_LINK to ADD_LINK transition When smc_llc_event_handler() transitions the local LLC flow from SMC_LLC_FLOW_REQ_ADD_LINK to SMC_LLC_FLOW_ADD_LINK on arrival of an ADD_LINK request, it calls smc_llc_flow_qentry_set() unconditionally: if (lgr->llc_flow_lcl.type == SMC_LLC_FLOW_REQ_ADD_LINK) { lgr->llc_flow_lcl.type = SMC_LLC_FLOW_ADD_LINK; smc_llc_flow_qentry_set(&lgr->llc_flow_lcl, qentry); ... } A CONFIRM_LINK or ADD_LINK_CONT arriving while flow->type is SMC_LLC_FLOW_REQ_ADD_LINK is stashed into flow->qentry via the SMC_LLC_CONFIRM_LINK / SMC_LLC_ADD_LINK_CONT handler (which stores into flow->qentry for any non-NONE flow type). When the subsequent ADD_LINK arrives, the REQ_ADD_LINK branch overwrites flow->qentry with the new pointer without first freeing the stashed allocation, leaking one kmalloc object. The stashed entry has no consumer: smc_llc_wait() is only called from llc_add_link_work, which is not yet scheduled while the flow type remains REQ_ADD_LINK. No waiter is sleeping on llc_msg_waiter at this point. It is safe to unconditionally free any stashed qentry before the overwrite. Call smc_llc_flow_qentry_del() before smc_llc_flow_qentry_set() in the REQ_ADD_LINK branch. smc_llc_flow_qentry_del() already checks flow->qentry before freeing, so the normal path where no entry is stashed is a no-op.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
b4ba4652b3f8b7c9bbb5786f8acf4724bdab2196 < 7dd55348c0d9399a9448847819e9f3904ae507ad b4ba4652b3f8b7c9bbb5786f8acf4724bdab2196 < 056395acb7041b3a1f2baa08d89a1938a8b8776a b4ba4652b3f8b7c9bbb5786f8acf4724bdab2196 < b08aacfb226a840628151643b6a34eecf545d311 b4ba4652b3f8b7c9bbb5786f8acf4724bdab2196 < 0fb9a513766071ea9d5f3bf988e39241b8e9ee3b b4ba4652b3f8b7c9bbb5786f8acf4724bdab2196 < e25a602c45c76a7130878db72bcf6f76df04bf85 b4ba4652b3f8b7c9bbb5786f8acf4724bdab2196 < 036322025d6e440cb75fc6fecbba9a16b271a2ae
Linux / Linux
5.16

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/7dd55348c0d9399a9448847819e9f3904ae507ad git.kernel.org: https://git.kernel.org/stable/c/056395acb7041b3a1f2baa08d89a1938a8b8776a git.kernel.org: https://git.kernel.org/stable/c/b08aacfb226a840628151643b6a34eecf545d311 git.kernel.org: https://git.kernel.org/stable/c/0fb9a513766071ea9d5f3bf988e39241b8e9ee3b git.kernel.org: https://git.kernel.org/stable/c/e25a602c45c76a7130878db72bcf6f76df04bf85 git.kernel.org: https://git.kernel.org/stable/c/036322025d6e440cb75fc6fecbba9a16b271a2ae