Review reviewHigh

CVE-2026-64048

Linux

In the Linux kernel, the following vulnerability has been resolved: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot On the SMC-D client, slot 0 of ini->ism_dev[]/ini->ism_chid[] is reserved for an SMC-Dv1 device. smc_find_ism_v2_device_clnt() populates V2 entries starting at index 1, so when no V1 device is selected slot 0 is left in its kzalloc()'ed state with ism_dev[0] == NULL and ism_chid[0] == 0. smc_v2_determine_accepted_chid() then matches the peer's CHID against the array starting from index 0 using the CHID alone. A malicious peer replying to a SMC-Dv2-only proposa...

CVSS
7.5
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.07.20
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7.5

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot On the SMC-D client, slot 0 of ini->ism_dev[]/ini->ism_chid[] is reserved for an SMC-Dv1 device. smc_find_ism_v2_device_clnt() populates V2 entries starting at index 1, so when no V1 device is selected slot 0 is left in its kzalloc()'ed state with ism_dev[0] == NULL and ism_chid[0] == 0. smc_v2_determine_accepted_chid() then matches the peer's CHID against the array starting from index 0 using the CHID alone. A malicious peer replying to a SMC-Dv2-only proposa...

Affected product and versions

Product
Linux
Affected versions
>= a7c9c5f4af7f6098da68705fc5d86565d0728ef7 < 6927cacf2b10d4fa80c1a2d407512ef9397c59c6, >= a7c9c5f4af7f6098da68705fc5d86565d0728ef7 < d38ba387244e5c5f7db3e11ea98bc2c7beccb0c0, >= a7c9c5f4af7f6098da68705fc5d86565d0728ef7 < 53eb7bd09aace72fa17510d80e0caf5ca058c231, >= a7c9c5f4af7f6098da68705fc5d86565d0728ef7 < afa9036b8c9963947b487c36e332df6a42c96fcb, >= a7c9c5f4af7f6098da68705fc5d86565d0728ef7 < 65edb3b0822cfe5041be8fbabebd57e2e5ad9f4e, >= a7c9c5f4af7f6098da68705fc5d86565d0728ef7 < 277740023def559a4a2ddc3e8e784ee37a0f16a9, >= 5.10
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE
Not available