PT-2026-51734 · Linux+2 · Linux Kernel+2

CVE-2026-52941

·

Published

2026-05-12

·

Updated

2026-09-07

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A NULL pointer dereference exists in the smc msg event tracepoint class, which is shared by smc tx sendmsg() and smc rx recvmsg(). The issue occurs because the system unconditionally dereferences smc->conn.lnk to access ibname. While conn->lnk is set for SMC-R, it remains NULL for SMC-D. When the tracepoint is enabled, the first sendmsg() or recvmsg() call on an SMC-D socket triggers a general protection fault. Although enabling the tracepoint requires root privileges, the trigger can be activated by an unprivileged user as socket(AF SMC, ...) lacks capability checks and SMC-D negotiation does not require administrative steps on s390 or x86 with the loopback ISM device loaded.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-90815
BDU:2026-13912
CVE-2026-52941
ECHO-A540-83FA-7BF7
OPENSUSE-SU-2026:21555-1
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23193-1
SUSE-SU-2026:23194-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
SUSE-SU-2026:23241-1
SUSE-SU-2026:23244-1
SUSE-SU-2026:3790-1
SUSE-SU-2026:3810-1
USN-8566-1
USN-8568-1
USN-8569-1
USN-8593-1
USN-8603-1
USN-8618-1
USN-8663-1
USN-8664-1
USN-8728-1
USN-8729-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu