{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80982","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.811Z","datePublished":"2026-09-11T19:42:42.243Z","dateUpdated":"2026-09-14T11:59:25.672Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T11:59:25.672Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: fix use-after-free in smc_rx_pipe_buf_release()\n\nsmc_rx_splice() hands RMB pages to a pipe and takes a socket reference\nper entry so the smc_sock stays alive until the reader finishes. The\nconnection does not: a concurrent close runs smc_conn_free(), which\nreleases the receive buffer back to the link group pool.\n\nsmc_rx_pipe_buf_release() tests sk_state before taking the socket lock.\nThe state can change between the test and the lock, and\nsmc_rx_update_cons() then dereferences conn->rmb_desc and walks\nconn->lgr, which smc_conn_free() has already released. On the\nis_reg_err path smcr_buf_unuse() frees the descriptor outright, so\nthis is a use-after-free.\n\nTake the socket lock first and test conn->freed instead.\nsmc_conn_free() sets that flag before releasing anything, and every\ncaller holds the socket lock. The two paths exclude each other: either\nthe pipe release runs first with everything valid, or it sees the flag\nand skips the update."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The UAF is in smc_rx_pipe_buf_release(), a pipe_buf_ops.release callback reached only via local splice() on an AF_SMC socket (syscall -> sock_splice_read -> smc_splice_read -> smc_rx_recvmsg -> smc_rx_splice). A remote SMC peer can supply RMB data or close the connection, but cannot invoke the splice pipe-buffer release path by itself.\nAC:L - The attacker controls both sides of the TOCTOU: one thread splices SMC Rx data into a pipe and then reads or closes it (unlocked sk_state check, then lock_sock), while another closes the socket so smc_conn_free() drops rmb_desc/lgr in that window. The race is fully attacker-driven and retryable.\nPR:L - socket(AF_SMC) or IPPROTO_SMC, connect/listen (loopback-ism, ISM, or RoCE), splice(2), and close(2) have no capability checks and are available to an unprivileged local user. User-namespace admin rights are not required.\nUI:N - A single unprivileged process can act as both SMC endpoints on loopback or a local fabric, splice received data into a pipe, and race close() against pipe-buffer release. No victim user action is required.\nS:U - The corruption is confined to kernel objects (smc_buf_desc, smc_link_group) in the same kernel security authority. This is standard kernel memory corruption, not a VM, IOMMU, or sandbox boundary escape.\nC:H - smc_rx_update_cons() dereferences conn->rmb_desc and walks conn->lgr after smc_conn_free()/smcr_buf_unuse() released them; on the is_reg_err path smc_buf_free() frees the descriptor outright. Per kernel CVSS guidance, this UAF of heap objects enables arbitrary kernel-memory disclosure.\nI:H - The same UAF writes consumer cursors and may call smc_tx_consumer_update() -> smc_cdc_get_slot_and_msg_send() or queue_delayed_work on conn->lgr->tx_wq after the link group is freed, enabling heap reuse, arbitrary write, and control-flow hijack.\nA:H - Dereferencing the freed rmb_desc or link group produces a kernel oops or panic. Use-after-free on this path crashes the host even when not fully exploited, and the attacker can repeat the race at will."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/smc/smc_rx.c"],"versions":[{"version":"9014db202cb764b8e14c53e7bacc81f9a1a2ba7f","lessThan":"dadd97c8296b23aa816e91ed70041820ae087baa","status":"affected","versionType":"git"},{"version":"9014db202cb764b8e14c53e7bacc81f9a1a2ba7f","lessThan":"df441f3efbb50eb0f120b8de4bf441c31fb0551d","status":"affected","versionType":"git"},{"version":"9014db202cb764b8e14c53e7bacc81f9a1a2ba7f","lessThan":"6a644a7340df978785f3109d1e0726a982ce2c6f","status":"affected","versionType":"git"},{"version":"9014db202cb764b8e14c53e7bacc81f9a1a2ba7f","lessThan":"0761e49aa78c2f1362511054c6e9670653858837","status":"affected","versionType":"git"},{"version":"9014db202cb764b8e14c53e7bacc81f9a1a2ba7f","lessThan":"0926f59ca0f94120895b92180c636a48d0ed3a6d","status":"affected","versionType":"git"},{"version":"9014db202cb764b8e14c53e7bacc81f9a1a2ba7f","lessThan":"c924884743e948e25625b7fbf3ee2a9325a204a7","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/smc/smc_rx.c"],"versions":[{"version":"4.18","status":"affected"},{"version":"0","lessThan":"4.18","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.18","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.18","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.18","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.18","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.18","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.18","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/dadd97c8296b23aa816e91ed70041820ae087baa"},{"url":"https://git.kernel.org/stable/c/df441f3efbb50eb0f120b8de4bf441c31fb0551d"},{"url":"https://git.kernel.org/stable/c/6a644a7340df978785f3109d1e0726a982ce2c6f"},{"url":"https://git.kernel.org/stable/c/0761e49aa78c2f1362511054c6e9670653858837"},{"url":"https://git.kernel.org/stable/c/0926f59ca0f94120895b92180c636a48d0ed3a6d"},{"url":"https://git.kernel.org/stable/c/c924884743e948e25625b7fbf3ee2a9325a204a7"}],"title":"net/smc: fix use-after-free in smc_rx_pipe_buf_release()","x_generator":{"engine":"bippy-1.2.0"}}}}