Bug 2502589 (CVE-2026-64048) - CVE-2026-64048 kernel: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot
Summary: CVE-2026-64048 kernel: net/smc: reject CHID-0 ACCEPT that matches an empty is...
Keywords:
Status: NEW
Alias: CVE-2026-64048
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-19 17:07 UTC by OSIDB Bzimport
Modified: 2026-08-20 05:13 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:57252 0 None None None 2026-08-20 05:13:31 UTC
Red Hat Product Errata RHSA-2026:57253 0 None None None 2026-08-20 04:24:33 UTC
Red Hat Product Errata RHSA-2026:57254 0 None None None 2026-08-20 03:42:28 UTC

Description OSIDB Bzimport 2026-07-19 17:07:44 UTC
In the Linux kernel, the following vulnerability has been resolved:

net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot

On the SMC-D client, slot 0 of ini->ism_dev[]/ini->ism_chid[] is
reserved for an SMC-Dv1 device. smc_find_ism_v2_device_clnt()
populates V2 entries starting at index 1, so when no V1 device is
selected slot 0 is left in its kzalloc()'ed state with ism_dev[0] ==
NULL and ism_chid[0] == 0.

smc_v2_determine_accepted_chid() then matches the peer's CHID against
the array starting from index 0 using the CHID alone. A malicious
peer replying to a SMC-Dv2-only proposal with d1.chid == 0 matches
the empty slot, ini->ism_selected becomes 0, and the subsequent
ism_dev[0]->lgr_lock dereference in smc_conn_create() faults at
offsetof(struct smcd_dev, lgr_lock) == 0x68:

  BUG: KASAN: null-ptr-deref in _raw_spin_lock_bh+0x79/0xe0
  Write of size 4 at addr 0000000000000068 by task exploit/144
  Call Trace:
   _raw_spin_lock_bh
   smc_conn_create (net/smc/smc_core.c:1997)
   __smc_connect (net/smc/af_smc.c:1447)
   smc_connect (net/smc/af_smc.c:1720)
   __sys_connect
   __x64_sys_connect
   do_syscall_64

Require ism_dev[i] to be non-NULL before accepting a CHID match.

Comment 4 errata-xmlrpc 2026-08-20 03:42:27 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:57254 https://access.redhat.com/errata/RHSA-2026:57254

Comment 5 errata-xmlrpc 2026-08-20 04:24:32 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:57253 https://access.redhat.com/errata/RHSA-2026:57253

Comment 6 errata-xmlrpc 2026-08-20 05:13:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:57252 https://access.redhat.com/errata/RHSA-2026:57252


Note You need to log in before you can comment on or make changes to this bug.