« Volver al listado

CVE-2026-80979

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

net/smc: unregister the connection before draining the rx tasklet

smc_conn_free() calls smc_ism_unset_conn() only while the link group is still on its device list, and never sets conn->killed. smc_lgr_terminate_sched() unlinks the group immediately and defers killing its connections to a work item, so a connection freed in that window keeps its smcd->conn[] slot with both gates in smcd_handle_irq() open, and the device can re-arm the receive tasklet after tasklet_kill() has returned. On the DMB-nocopy path the ghost send buffer is freed right after that drain, so the re-armed tasklet dereferences it.

Leer descripción completaMostrar menos

Unregister unconditionally and drain before the detach at both teardown sites, mirroring rmb_desc, which smc_buf_unuse() releases after the drain. Clear conn->sndbuf_desc before freeing it as well, so a reader that samples the pointer cannot get one that is already freed.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad local con privilegios (PR:L) en kernel Linux que permite DoS y corrupción de memoria mediante race condition en SMC; el atacante obtiene acceso a nivel de kernel (T1068) tras explotar la gestión incorrecta de buffers de envío y tasklets.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80979",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "21f6f41e82e59740e26e06e77bdf58dc7f6f08dd",
              "lessThan": "b6b6ac713ee82b340a8e3be30b101bd2840deec4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ae2be35cbed2c8385e890147ea321a3fcc3ca5fa",
              "lessThan": "b4d540ac95cd35c6ebab6afb7eae2bcac7b277a5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ae2be35cbed2c8385e890147ea321a3fcc3ca5fa",
              "lessThan": "5bd8b764a610b6b6bc0c4d3d01652747f6e0b5c3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ae2be35cbed2c8385e890147ea321a3fcc3ca5fa",
              "lessThan": "b74d313567dfc1b7e56629ddbad04e728686f235",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ae2be35cbed2c8385e890147ea321a3fcc3ca5fa",
              "lessThan": "36cdf5d48ca191dcd71c28cadbe0981b1d25318d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.6.66",
              "lessThan": "6.6.157",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "net/smc/smc_core.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.10"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.10",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.109",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.50",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/smc/smc_core.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:19:04.277",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/36cdf5d48ca191dcd71c28cadbe0981b1d25318d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5bd8b764a610b6b6bc0c4d3d01652747f6e0b5c3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b4d540ac95cd35c6ebab6afb7eae2bcac7b277a5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b6b6ac713ee82b340a8e3be30b101bd2840deec4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b74d313567dfc1b7e56629ddbad04e728686f235",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: unregister the connection before draining the rx tasklet\n\nsmc_conn_free() calls smc_ism_unset_conn() only while the link group is\nstill on its device list, and never sets conn->killed.\nsmc_lgr_terminate_sched() unlinks the group immediately and defers killing\nits connections to a work item, so a connection freed in that window keeps\nits smcd->conn[] slot with both gates in smcd_handle_irq() open, and the\ndevice can re-arm the receive tasklet after tasklet_kill() has returned. On\nthe DMB-nocopy path the ghost send buffer is freed right after that drain,\nso the re-armed tasklet dereferences it.\n\nUnregister unconditionally and drain before the detach at both teardown\nsites, mirroring rmb_desc, which smc_buf_unuse() releases after the drain.\nClear conn->sndbuf_desc before freeing it as well, so a reader that samples\nthe pointer cannot get one that is already freed."
    }
  ],
  "lastModified": "2026-09-14T13:18:52.803",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}