Ad

CVE-2026-80984

NONE EPSS 0.21%
Обновлено 14 сентября 2026
Linux
Параметр Значение
Поставщик Linux
Публичный эксплойт Нет

В ядре Linux устранена следующая уязвимость: net/smc: не разыменовывать неустановленный буфер отправки на пути удаления SMC-D. smc_close_stream_wait() вызывает smc_tx_prepared_sends() изнутри своего условие sk_wait_event(), а sk_wait_event() оценивает это условие. один раз с отпущенным фиксатором розетки. smcd_buf_detach() очищает conn->sndbuf_desc из smc_conn_kill() под lock_sock(), поэтому группа ссылок завершение, пока сокет ожидает, приводит к разыменовыванию помощника NULL, ошибка закрытия(). SIOCOUTQ читает поле вручную и smc_close_cancel_work() снимает блокировку между двумя вызовами cancel_*_sync(). Попробуйте указатель один раз в помощнике, не сообщайте ничего подготовленного, пока он находится unset и таким же образом связал ioctl. Разыменования тасклета получения поле непосредственно в smc_cdc_msg_recv_action(), а не через этот помощник; 1/2 — это то, что не дает ему работать так поздно.

Показать оригинальное описание (EN)

In the Linux kernel, the following vulnerability has been resolved: net/smc: do not dereference an unset send buffer on the SMC-D teardown path smc_close_stream_wait() calls smc_tx_prepared_sends() from inside its sk_wait_event() condition, and sk_wait_event() evaluates that condition once with the socket lock released. smcd_buf_detach() clears conn->sndbuf_desc from smc_conn_kill() under lock_sock(), so a link group terminating while a socket waits there leaves the helper dereferencing NULL, faulting out of close(). SIOCOUTQ reads the field by hand, and smc_close_cancel_work() drops the lock across two cancel_*_sync() calls. Sample the pointer once in the helper, report nothing prepared while it is unset, and bound the ioctl the same way. The receive tasklet dereferences the field directly in smc_cdc_msg_recv_action(), not through this helper; 1/2 is what keeps it from running that late.