Use-After-Free Vulnerability in Linux Kernel's SMC-R Implementation
CVE-2026-64541

9.8CRITICAL

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-64541?

A use-after-free vulnerability exists in the SMC-R implementation of the Linux kernel. This issue arises from insufficient reference pinning of sockets during connection handling. The vulnerability occurs when the smc_cdc_rx_handler function dereferences a socket after the associated lock has been released, allowing for a potential race condition that could lead to kernel panic or other erratic behaviors. This issue specifically affects only the SMC-R protocol, as the SMC-D tasklet is correctly managed. It's vital to apply the necessary security patches to prevent exploitation of this vulnerability.

Affected Version(s)

Linux d7b0e37c1ac152905b18a5b9506179091a35b0b6 < 8de4f665d0febfb92803dece377791a563fc7041

Linux d7b0e37c1ac152905b18a5b9506179091a35b0b6 < 8145b432136285e01091815b48ceb2dae261f262

Linux d7b0e37c1ac152905b18a5b9506179091a35b0b6 < 1951bffbc6493ec34cff3956b29d4bc6606904a6

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.