PT-2026-61365 · Linux+2 · Linux Kernel+2

CVE-2026-64048

·

Published

2026-05-14

·

Updated

2026-09-07

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the SMC-D client where the system fails to properly validate the ism dev slot when processing a CHID-0 ACCEPT. Specifically, the smc v2 determine accepted chid() function matches a peer's CHID against an array starting from index 0. If a malicious peer responds to an SMC-Dv2-only proposal with d1.chid equal to 0, it can match an empty slot where ism dev[0] is NULL. This leads to a null-pointer dereference in the smc conn create() function when attempting to access the lgr lock within the smcd dev structure, resulting in a system fault.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:57252
ALSA-2026:57253
ALSA-2026:57254
BDU:2026-14420
CVE-2026-64048
USN-8593-1
USN-8603-1
USN-8618-1
USN-8663-1
USN-8664-1
USN-8728-1
USN-8729-1

Affected Products

Linux Kernel
Rocky Linux
Ubuntu