Use-After-Free Vulnerability in Linux Kernel's SMC-R Implementation
CVE-2026-64541
What is CVE-2026-64541?
A use-after-free vulnerability exists in the SMC-R implementation of the Linux kernel. This issue arises from insufficient reference pinning of sockets during connection handling. The vulnerability occurs when the smc_cdc_rx_handler function dereferences a socket after the associated lock has been released, allowing for a potential race condition that could lead to kernel panic or other erratic behaviors. This issue specifically affects only the SMC-R protocol, as the SMC-D tasklet is correctly managed. It's vital to apply the necessary security patches to prevent exploitation of this vulnerability.
Affected Version(s)
Linux d7b0e37c1ac152905b18a5b9506179091a35b0b6 < 8de4f665d0febfb92803dece377791a563fc7041
Linux d7b0e37c1ac152905b18a5b9506179091a35b0b6 < 8145b432136285e01091815b48ceb2dae261f262
Linux d7b0e37c1ac152905b18a5b9506179091a35b0b6 < 1951bffbc6493ec34cff3956b29d4bc6606904a6