PT-2026-90110 · Linux · Linux
CVE-2026-80980
·
Publicado
2026-09-11
·
Atualizado
2026-09-11
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
net/smc: stop killed, freed and out of sync sharing a byte
The three connection state flags are single-bit bitfields, so they occupy
one byte of struct smc connection and every store to one is a
read-modify-write of the other two:
u8 killed : 1;
u8 freed : 1;
u8 out of sync : 1;
They are not written under a common lock. smc cdc msg validate() sets
out of sync from the receive tasklet, while smc conn kill() sets killed
from process context under lock sock(), and the receive path does not defer
to the backlog when the socket is owned -- smc cdc msg recv() takes only
bh lock sock().
Give each flag its own byte so a store no longer touches its neighbours.
All readers test them as booleans and are unchanged. struct smc connection
grows by two bytes.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux