CVE-2026-64048
Last modified
CVE-2026-64048 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot On the SMC-D client, slot 0 of ini->ism_dev[]/ini->ism_chid[] is reserved for an SMC-Dv1 device. smc_find_ism_v2_device_clnt() populates V2 entries starting at index 1, so when no V1 device is selected slot 0 is left in its kzalloc()'ed state with ism_dev[0] == NULL and ism_chid[0] == 0. smc_v2_determine_accepted_chid() then matches the peer's CHID against the array starting from index 0 using the CHID alone. EPSS estimates a 0.48% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot On the SMC-D client, slot 0 of ini->ism_dev[]/ini->ism_chid[] is reserved for an SMC-Dv1 device. smc_find_ism_v2_device_clnt() populates V2 entries starting at index 1, so when no V1 device is selected slot 0 is left in its kzalloc()'ed state with ism_dev[0] == NULL and ism_chid[0] == 0. smc_v2_determine_accepted_chid() then matches the peer's CHID against the array starting from index 0 using the CHID alone. A malicious peer replying to a SMC-Dv2-only proposal with d1.chid == 0 matches the empty slot, ini->ism_selected becomes 0, and the subsequent ism_dev[0]->lgr_lock dereference in smc_conn_create() faults at offsetof(struct smcd_dev, lgr_lock) == 0x68: BUG: KASAN: null-ptr-deref in _raw_spin_lock_bh+0x79/0xe0 Write of size 4 at addr 0000000000000068 by task exploit/144 Call Trace: _raw_spin_lock_bh smc_conn_create (net/smc/smc_core.c:1997) __smc_connect (net/smc/af_smc.c:1447) smc_connect (net/smc/af_smc.c:1720) __sys_connect __x64_sys_connect do_syscall_64 Require ism_dev[i] to be non-NULL before accepting a CHID match.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= a7c9c5f4af7f6098da68705fc5d86565d0728ef7, < 6927cacf2b10d4fa80c1a2d407512ef9397c59c6; >= a7c9c5f4af7f6098da68705fc5d86565d0728ef7, < d38ba387244e5c5f7db3e11ea98bc2c7beccb0c0; >= a7c9c5f4af7f6098da68705fc5d86565d0728ef7, < 53eb7bd09aace72fa17510d80e0caf5ca058c231; >= a7c9c5f4af7f6098da68705fc5d86565d0728ef7, < afa9036b8c9963947b487c36e332df6a42c96fcb; >= a7c9c5f4af7f6098da68705fc5d86565d0728ef7, < 65edb3b0822cfe5041be8fbabebd57e2e5ad9f4e; >= a7c9c5f4af7f6098da68705fc5d86565d0728ef7, < 277740023def559a4a2ddc3e8e784ee37a0f16a9 |
| Linux | Linux | 5.10 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-64048?
How severe is CVE-2026-64048?
How do I fix CVE-2026-64048?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-64042In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-64043In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64044In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64045In the Linux kernel, the following vulnerability has been re…8.4
- CVE-2026-64046In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-64047In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-64049In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6405The Anomify AI – Anomaly Detection and Alerting plugin for W…4.3
- CVE-2026-64050In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64051In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-64052In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64053In the Linux kernel, the following vulnerability has been re…7.8
Are you affected by CVE-2026-64048?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
