CVE-2026-64541
In the Linux kernel, the following vulnerability has been resolved:
net/smc: fix UAF in smccdcrx_handler() by pinning the socket
smccdcrx_handler() looks up the connection by token under the link
group's conns_lock, drops the lock, and then dereferences conn and the
smcsock derived from it, ending in sockhold(&smc->sk) inside
smccdcmsg_recv(). No reference is held across the lock release.
The only reference pinning the socket while the connection is
discoverable in the link group is taken in smclgrregister_conn()
(sockhold) and dropped in smclgrunregisterconn() (sock_put), both
under connslock. Once the handler drops connslock, a concurrent
close() -> smcrelease() -> smcconnfree() -> smclgrunregisterconn()
can drop that reference and free the smc_sock, so the handler's later
sock_hold() runs on freed memory:
WARNING: lib/refcount.c:25 at refcountwarnsaturate
Workqueue: rxewq dowork
refcountwarnsaturate (lib/refcount.c:25)
smccdcmsgrecv (net/smc/smccdc.c:430)
smccdcrxhandler (net/smc/smccdc.c:502)
smcwrrxtaskletfn (net/smc/smc_wr.c:445)
taskletactioncommon (kernel/softirq.c:938)
handle_softirqs (kernel/softirq.c:622)
Kernel panic - not syncing: paniconwarn set
Only SMC-R is affected. The SMC-D receive tasklet is stopped by
taskletkill(&conn->rxtsklet) in smcconnfree() before the connection
is unregistered, so it cannot run concurrently with the free.
Take the socket reference while still holding conns_lock, so the
registration reference can no longer be the last one, and drop it once
the handler is done.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/1951bffbc6493ec34cff3956b29d4bc6606904a6, https://git.kernel.org/stable/c/3bfb96d9bc6a7ed0b99c7db329cc2e22a28d84bb, https://git.kernel.org/stable/c/472e9d7c0d5b03be3ff91ff941f57da822b031bc, https://git.kernel.org/stable/c/647b19e5cc145a2f1f685ae8ff3805a17356888c, https://git.kernel.org/stable/c/8145b432136285e01091815b48ceb2dae261f262, https://git.kernel.org/stable/c/8de4f665d0febfb92803dece377791a563fc7041, https://git.kernel.org/stable/c/9d160b35cc34a2ba8229d07651468a7848325135, https://git.kernel.org/stable/c/ce5aa8084329351086894aa34d77e40301d5bd3d, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64541.json, https://nvd.nist.gov/vuln/detail/CVE-2026-64541, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git