CVE-2026-90108
CVE CVE-2026-90108EUVD EUVD-2026-81701Published 2026-09-17T16:06:16.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: net/smc: free stashed qentry before overwrite in REQ_ADD_LINK to ADD_LINK transition When smc_llc_event_handler() transitions the local LLC flow from SMC_LLC_FLOW_REQ_ADD_LINK to SMC_LLC_FLOW_ADD_LINK on arrival of an ADD_LINK request, it calls smc_llc_flow_qentry_set() unconditionally: if (lgr->llc_flow_lcl.type == SMC_LLC_FLOW_REQ_ADD_LINK) { lgr->llc_flow_lcl.type = SMC_LLC_FLOW_ADD_LINK; smc_llc_flow_qentry_set(&lgr->llc_flow_lcl, qentry); ... } A CONFIRM_LINK or ADD_LINK_CONT arriving while flow->type is SMC_LLC_FLOW_REQ_ADD_LINK is stashed into flow->qentry via the SMC_LLC_CONFIRM_LINK / SMC_LLC_ADD_LINK_CONT handler (which stores into flow->qentry for any non-NONE flow type). When the subsequent ADD_LINK arrives, the REQ_ADD_LINK branch overwrites flow->qentry with the new pointer without first freeing the stashed allocation, leaking one kmalloc object. The stashed entry has no consumer: smc_llc_wait() is only called from llc_add_link_work, which is not yet scheduled while the flow type remains REQ_ADD_LINK. No waiter is sleeping on llc_msg_waiter at this point. It is safe to unconditionally free any stashed qentry before the overwrite. Call smc_llc_flow_qentry_del() before smc_llc_flow_qentry_set() in the REQ_ADD_LINK branch. smc_llc_flow_qentry_del() already checks flow->qentry before freeing, so the normal path where no entry is stashed is a no-op.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux b4ba4652b3f8b7c9bbb5786f8acf4724bdab2196 <7dd55348c0d9399a9448847819e9f3904ae507ad; patch: 7.3-rc1; patch: 6.1.188; patch: 0; b4ba4652b3f8b7c9bbb5786f8acf4724bdab2196 <056395acb7041b3a1f2baa08d89a1938a8b8776a; b4ba4652b3f8b7c9bbb5786f8acf4724bdab2196 <036322025d6e440cb75fc6fecbba9a16b271a2ae; b4ba4652b3f8b7c9bbb5786f8acf4724bdab2196 <b08aacfb226a840628151643b6a34eecf545d311; patch: 6.6.157; b4ba4652b3f8b7c9bbb5786f8acf4724bdab2196 <e25a602c45c76a7130878db72bcf6f76df04bf85; 5.16; b4ba4652b3f8b7c9bbb5786f8acf4724bdab2196 <0fb9a513766071ea9d5f3bf988e39241b8e9ee3b; patch: 6.18.52; patch: 6.12.110; patch: 7.2.6
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.