PT-2026-90110 · Linux · Linux

CVE-2026-80980

·

Publicado

2026-09-11

·

Atualizado

2026-09-11

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
net/smc: stop killed, freed and out of sync sharing a byte
The three connection state flags are single-bit bitfields, so they occupy one byte of struct smc connection and every store to one is a read-modify-write of the other two:
u8 killed : 1; u8 freed : 1; u8 out of sync : 1;
They are not written under a common lock. smc cdc msg validate() sets out of sync from the receive tasklet, while smc conn kill() sets killed from process context under lock sock(), and the receive path does not defer to the backlog when the socket is owned -- smc cdc msg recv() takes only bh lock sock().
Give each flag its own byte so a store no longer touches its neighbours. All readers test them as booleans and are unchanged. struct smc connection grows by two bytes.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-80980

Produtos afetados

Linux