« Volver al listado

CVE-2026-90107

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

net/smc: free pending qentry in smc_llc_flow_stop() before memset

smc_llc_flow_stop() resets a flow struct with a blind memset:

If flow->qentry is non-NULL at this point the pointer is overwritten without the allocation being freed, leaking one kmalloc object.

A late-arriving duplicate CONFIRM_LINK or ADD_LINK_CONT message can set flow->qentry after the legitimate message has been consumed by the waiter via smc_llc_flow_qentry_clr() (which NULLs the pointer but leaves flow->type non-zero) but before the flow completes and smc_llc_flow_stop() runs. In that window the duplicate is stashed into flow->qentry, and then lost when smc_llc_flow_stop() zeros the struct.

Leer descripción completaMostrar menos

Call smc_llc_flow_qentry_del() inside the lock before the memset. smc_llc_flow_qentry_del() already checks flow->qentry before freeing, so the normal case where no entry is pending is a no-op.

Detalles técnicos trazas, registros y código del informe original
	spin_lock_bh(&lgr->llc_flow_lock);
	memset(flow, 0, sizeof(*flow));
	flow->type = SMC_LLC_FLOW_NONE;
	spin_unlock_bh(&lgr->llc_flow_lock);

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90107",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "555da9af827d95134656fa459c8f3ece04dd867a",
              "lessThan": "8e3deb150a5237b672c4579e69a6deb02027dbed",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "555da9af827d95134656fa459c8f3ece04dd867a",
              "lessThan": "11bc373ee6630709f0c2da2e7860c23d503c9e9d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "555da9af827d95134656fa459c8f3ece04dd867a",
              "lessThan": "032aec7d03c9102616b98fea74f8f7145e7f867c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "555da9af827d95134656fa459c8f3ece04dd867a",
              "lessThan": "957dba2b8b5aebfe09caa6a6b22b958079082eab",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "555da9af827d95134656fa459c8f3ece04dd867a",
              "lessThan": "f03aa5d36ae3c4068a1c3885146be99aa7fd9307",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "555da9af827d95134656fa459c8f3ece04dd867a",
              "lessThan": "0879ea157acc1ac6752f6fcb755d1f91a2359238",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "555da9af827d95134656fa459c8f3ece04dd867a",
              "lessThan": "5ff429dd6725fa6c1e17a4ed0be8ab675f67a98b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "555da9af827d95134656fa459c8f3ece04dd867a",
              "lessThan": "5ee0ceddc7785c6dcf4a8107fef01f0414a354f4",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/smc/smc_llc.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.8"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.8",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.270",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/smc/smc_llc.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:02.570",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/032aec7d03c9102616b98fea74f8f7145e7f867c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/0879ea157acc1ac6752f6fcb755d1f91a2359238",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/11bc373ee6630709f0c2da2e7860c23d503c9e9d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5ee0ceddc7785c6dcf4a8107fef01f0414a354f4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5ff429dd6725fa6c1e17a4ed0be8ab675f67a98b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8e3deb150a5237b672c4579e69a6deb02027dbed",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/957dba2b8b5aebfe09caa6a6b22b958079082eab",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f03aa5d36ae3c4068a1c3885146be99aa7fd9307",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: free pending qentry in smc_llc_flow_stop() before memset\n\nsmc_llc_flow_stop() resets a flow struct with a blind memset:\n\n\tspin_lock_bh(&lgr->llc_flow_lock);\n\tmemset(flow, 0, sizeof(*flow));\n\tflow->type = SMC_LLC_FLOW_NONE;\n\tspin_unlock_bh(&lgr->llc_flow_lock);\n\nIf flow->qentry is non-NULL at this point the pointer is overwritten without the\nallocation being freed, leaking one kmalloc object.\n\nA late-arriving duplicate CONFIRM_LINK or ADD_LINK_CONT message can set\nflow->qentry after the legitimate message has been consumed by the waiter via\nsmc_llc_flow_qentry_clr() (which NULLs the pointer but leaves flow->type\nnon-zero) but before the flow completes and smc_llc_flow_stop() runs.  In that\nwindow the duplicate is stashed into flow->qentry, and then lost when\nsmc_llc_flow_stop() zeros the struct.\n\nCall smc_llc_flow_qentry_del() inside the lock before the memset.\nsmc_llc_flow_qentry_del() already checks flow->qentry before freeing, so the\nnormal case where no entry is pending is a no-op."
    }
  ],
  "lastModified": "2026-09-17T17:17:02.570",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}