« Volver al listado

CVE-2026-80985

Estado: RecibidaAlta (8.2)—

In the Linux kernel, the following vulnerability has been resolved:

net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry

smc_llc_rmt_delete_rkey() and smc_llc_save_add_link_rkeys() read the part of a v2 message that does not fit into the 44-byte union smc_llc_msg, and both bound themselves by the size of the buffer it landed in, not by what arrived. On a link with a shared v2 receive buffer a 44-byte DELETE_RKEY_V2 declaring 255 rkeys reaches rkey[9..254] in whatever an earlier message left in lgr->wr_rx_buf_v2, and passes each of them to smc_rtoken_delete(). One of those 255 matched a registered rtoken and deleted it. An ADD_LINK on such a link installs up to 255 rtokens from the same bytes.

Leer descripción completaMostrar menos

Copy the tail into the queue entry, so its length is the length of the message that arrived, and declare the rkeys that fit inline as a member of the union instead of reaching them through a cast. The same DELETE_RKEY_V2 now processes the 9 rkeys it carries. The copy is limited to the longest tail the two functions can read, so the peer does not pick the size of the entry.

The bound the previous patch placed on links without a shared v2 receive buffer is no longer needed.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Inferido por reglas deterministas a partir del vector CVSS y la CWE. Solo orientativo.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80985",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.2,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 4.2,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "27ef6a9981fe74191849966a6d5e0400a4008ab8",
              "lessThan": "edf30d65e3ac52f886f7d87b1a7449742e79157d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "27ef6a9981fe74191849966a6d5e0400a4008ab8",
              "lessThan": "0d6f80be8ac5886842640d6526abf3f9a215be75",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "27ef6a9981fe74191849966a6d5e0400a4008ab8",
              "lessThan": "8d3c1ab82c11d4fadebf817a825fd221b3e197ea",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/smc/smc_llc.c",
            "net/smc/smc_wr.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.14"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.14",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.50",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/smc/smc_llc.c",
            "net/smc/smc_wr.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:19:05.050",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0d6f80be8ac5886842640d6526abf3f9a215be75",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8d3c1ab82c11d4fadebf817a825fd221b3e197ea",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/edf30d65e3ac52f886f7d87b1a7449742e79157d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: carry oversized SMC-Rv2 LLC messages in the queue entry\n\nsmc_llc_rmt_delete_rkey() and smc_llc_save_add_link_rkeys() read the part\nof a v2 message that does not fit into the 44-byte union smc_llc_msg, and\nboth bound themselves by the size of the buffer it landed in, not by what\narrived. On a link with a shared v2 receive buffer a 44-byte\nDELETE_RKEY_V2 declaring 255 rkeys reaches rkey[9..254] in whatever an\nearlier message left in lgr->wr_rx_buf_v2, and passes each of them to\nsmc_rtoken_delete(). One of those 255 matched a registered rtoken and\ndeleted it. An ADD_LINK on such a link installs up to 255 rtokens from\nthe same bytes.\n\nCopy the tail into the queue entry, so its length is the length of the\nmessage that arrived, and declare the rkeys that fit inline as a member of\nthe union instead of reaching them through a cast. The same\nDELETE_RKEY_V2 now processes the 9 rkeys it carries. The copy is limited\nto the longest tail the two functions can read, so the peer does not pick\nthe size of the entry.\n\nThe bound the previous patch placed on links without a shared v2 receive\nbuffer is no longer needed."
    }
  ],
  "lastModified": "2026-09-13T07:17:05.290",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}