Answer in brief
CVE-2026-64541 records a Critical severity (CVSS 9.8) vulnerability in net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=d7b0e37c1ac152905b18a5b9506179091a35b0b6 <8de4f665d0febfb92803dece377791a563fc7041 || >=d7b0e37c1ac152905b18a5b9506179091a35b0b6 <8145b432136285e01091815b48ceb2dae261f262 || >=d7b0e37c1ac152905b18a5b9506179091a35b0b6 <1951bffbc6493ec34cff3956b29d4bc6606904a6 || >=d7b0e37c1ac152905b18a5b9506179091a35b0b6 <647b19e5cc145a2f1f685ae8ff3805a17356888c || >=d7b0e37c1ac152905b18a5b9506179091a35b0b6 <472e9d7c0d5b03be3ff91ff941f57da822b031bc || >=d7b0e37c1ac152905b18a5b9506179091a35b0b6 <3bfb96d9bc6a7ed0b99c7db329cc2e22a28d84bb || >=d7b0e37c1ac152905b18a5b9506179091a35b0b6 <ce5aa8084329351086894aa34d77e40301d5bd3d || >=d7b0e37c1ac152905b18a5b9506179091a35b0b6 <9d160b35cc34a2ba8229d07651468a7848325135 | 8de4f665d0febfb92803dece377791a563fc7041, 8145b432136285e01091815b48ceb2dae261f262, 1951bffbc6493ec34cff3956b29d4bc6606904a6, 647b19e5cc145a2f1f685ae8ff3805a17356888c, 472e9d7c0d5b03be3ff91ff941f57da822b031bc, 3bfb96d9bc6a7ed0b99c7db329cc2e22a28d84bb, ce5aa8084329351086894aa34d77e40301d5bd3d, 9d160b35cc34a2ba8229d07651468a7848325135 |
| Linux/Linuxgeneric | 4.18 | Not reported |
Published upstream
Jul 27, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket smc_cdc_rx_handler() looks up the connection by token under the link group's conns_lock, drops the lock, and then dereferences conn and the smc_sock derived from it, ending in sock_hold(&smc->sk) inside smc_cdc_msg_recv(). No reference is held across the lock release. The only reference pinning the socket while the connection is discoverable in the link group is taken in smc_lgr_register_conn() (sock_hold) and dropped in __smc_lgr_unregister_conn() (sock_put), both under conns_lock. Once the handler drops conns_lock, a concurrent close() -> smc_release() -> smc_conn_free() -> smc_lgr_unregister_conn() can drop that reference and free the smc_sock, so the handler's later sock_hold() runs on freed memory: WARNING: lib/refcount.c:25 at refcount_warn_saturate Workqueue: rxe_wq do_work refcount_warn_saturate (lib/refcount.c:25) smc_cdc_msg_recv (net/smc/smc_cdc.c:430) smc_cdc_rx_handler (net/smc/smc_cdc.c:502) smc_wr_rx_tasklet_fn (net/smc/smc_wr.c:445) tasklet_action_common (kernel/softirq.c:938) handle_softirqs (kernel/softirq.c:622) Kernel panic - not syncing: panic_on_warn set Only SMC-R is affected. The SMC-D receive tasklet is stopped by tasklet_kill(&conn->rx_tsklet) in smc_conn_free() before the connection is unregistered, so it cannot run concurrently with the free. Take the socket reference while still holding conns_lock, so the registration reference can no longer be the last one, and drop it once the handler is done.
Quoted source text, attributed separately from HOL analysis.