In the Linux kernel, the following vulnerability has been resolved:
net/smc: fix NULL sndbuf_desc in smc_cdc_tx_handler()
When performing a stress test on SMC-R by rmmod mlx5_ib driver during the wrk/nginx test, we found that there is a probability of triggering a panic while terminating all link groups.
This issue dues to the race between smc_smcr_terminate_all() and smc_buf_create().
smc_smcr_terminate_all
smc_buf_create /* init */ conn->sndbuf_desc = NULL; ...
__smc_lgr_terminate smc_conn_kill smc_close_abort smc_cdc_get_slot_and_msg_send
__softirqentry_text_start smc_wr_tx_process_cqe smc_cdc_tx_handler READ(conn->sndbuf_desc->len); /* panic dues to NULL sndbuf_desc */
conn->sndbuf_desc = xxx;
This patch tries to fix the issue by always to check the sndbuf_desc before send any cdc msg, to make sure that no null pointer is seen during cqe processing.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | May 5, 2025 | May 2, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 2, 2025 |
| Ubuntu | — | Upgrade linux-riscv-5.15Upgrade linux-oracle-5.15Upgrade linux-kvmUpgrade linux-xilinx-zynqmpUpgrade linux-intel-iotg-5.15Upgrade linux-lowlatencyUpgrade linux-intel-iotgUpgrade linux-gcp-5.15Upgrade linux-ibmUpgrade linux-azureUpgrade linux-azure-5.15Upgrade linux-nvidia-tegra-igxUpgrade linux-gkeUpgrade linux-nvidiaUpgrade linux-oracleUpgrade linux-gkeopUpgrade linux-realtimeUpgrade linuxUpgrade linux-lowlatency-hwe-5.15Upgrade linux-aws-5.15Upgrade linux-intel-iot-realtimeUpgrade linux-bluefieldUpgrade linux-nvidia-tegraUpgrade linux-hwe-5.15Upgrade linux-awsUpgrade linux-raspiUpgrade linux-gcpUpgrade linux-ibm-5.15Upgrade linux-nvidia-tegra-5.15 | May 8, 2025 | May 2, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | May 2, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub