PT-2026-94455 · Linux · Linux Kernel
CVE-2026-90107
·
Published
2026-09-17
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A memory leak occurs in the
net/smc module when the smc llc flow stop() function resets a flow structure using a blind memset(). If the flow->qentry variable is non-NULL, the pointer is overwritten without freeing the allocation, resulting in the leak of one kmalloc object. This condition can be triggered by a late-arriving duplicate CONFIRM LINK or ADD LINK CONT message that sets flow->qentry after a legitimate message has been processed by smc llc flow qentry clr() but before smc llc flow stop() is executed.Recommendations
Call the
smc llc flow qentry del() function inside the lock before the memset() operation to ensure any pending entries are freed.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel