Answer in brief
CVE-2026-90108 records a Unknown severity vulnerability in net/smc: free stashed qentry before overwrite in REQ_ADD_LINK to ADD_LINK transition. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=b4ba4652b3f8b7c9bbb5786f8acf4724bdab2196 <7dd55348c0d9399a9448847819e9f3904ae507ad || >=b4ba4652b3f8b7c9bbb5786f8acf4724bdab2196 <056395acb7041b3a1f2baa08d89a1938a8b8776a || >=b4ba4652b3f8b7c9bbb5786f8acf4724bdab2196 <b08aacfb226a840628151643b6a34eecf545d311 || >=b4ba4652b3f8b7c9bbb5786f8acf4724bdab2196 <0fb9a513766071ea9d5f3bf988e39241b8e9ee3b || >=b4ba4652b3f8b7c9bbb5786f8acf4724bdab2196 <e25a602c45c76a7130878db72bcf6f76df04bf85 || >=b4ba4652b3f8b7c9bbb5786f8acf4724bdab2196 <036322025d6e440cb75fc6fecbba9a16b271a2ae | 7dd55348c0d9399a9448847819e9f3904ae507ad, 056395acb7041b3a1f2baa08d89a1938a8b8776a, b08aacfb226a840628151643b6a34eecf545d311, 0fb9a513766071ea9d5f3bf988e39241b8e9ee3b, e25a602c45c76a7130878db72bcf6f76df04bf85, 036322025d6e440cb75fc6fecbba9a16b271a2ae |
| Linux/Linuxgeneric | 5.16 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: net/smc: free stashed qentry before overwrite in REQ_ADD_LINK to ADD_LINK transition When smc_llc_event_handler() transitions the local LLC flow from SMC_LLC_FLOW_REQ_ADD_LINK to SMC_LLC_FLOW_ADD_LINK on arrival of an ADD_LINK request, it calls smc_llc_flow_qentry_set() unconditionally: if (lgr->llc_flow_lcl.type == SMC_LLC_FLOW_REQ_ADD_LINK) { lgr->llc_flow_lcl.type = SMC_LLC_FLOW_ADD_LINK; smc_llc_flow_qentry_set(&lgr->llc_flow_lcl, qentry); ... } A CONFIRM_LINK or ADD_LINK_CONT arriving while flow->type is SMC_LLC_FLOW_REQ_ADD_LINK is stashed into flow->qentry via the SMC_LLC_CONFIRM_LINK / SMC_LLC_ADD_LINK_CONT handler (which stores into flow->qentry for any non-NONE flow type). When the subsequent ADD_LINK arrives, the REQ_ADD_LINK branch overwrites flow->qentry with the new pointer without first freeing the stashed allocation, leaking one kmalloc object. The stashed entry has no consumer: smc_llc_wait() is only called from llc_add_link_work, which is not yet scheduled while the flow type remains REQ_ADD_LINK. No waiter is sleeping on llc_msg_waiter at this point. It is safe to unconditionally free any stashed qentry before the overwrite. Call smc_llc_flow_qentry_del() before smc_llc_flow_qentry_set() in the REQ_ADD_LINK branch. smc_llc_flow_qentry_del() already checks flow->qentry before freeing, so the normal path where no entry is stashed is a no-op.
Quoted source text, attributed separately from HOL analysis.