CVE-2026-90108

Source
https://cve.org/CVERecord?id=CVE-2026-90108
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90108.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90108
Downstream
Published
2026-09-17T16:06:16Z
Modified
2026-09-18T03:48:35Z
Summary
net/smc: free stashed qentry before overwrite in REQ_ADD_LINK to ADD_LINK transition
Details

In the Linux kernel, the following vulnerability has been resolved:

net/smc: free stashed qentry before overwrite in REQ_ADD_LINK to ADD_LINK transition

When smc_llc_event_handler() transitions the local LLC flow from SMC_LLC_FLOW_REQ_ADD_LINK to SMC_LLC_FLOW_ADD_LINK on arrival of an ADD_LINK request, it calls smc_llc_flow_qentry_set() unconditionally:

if (lgr->llc_flow_lcl.type == SMC_LLC_FLOW_REQ_ADD_LINK) {
	lgr->llc_flow_lcl.type = SMC_LLC_FLOW_ADD_LINK;
	smc_llc_flow_qentry_set(&lgr->llc_flow_lcl, qentry);
	...
}

A CONFIRM_LINK or ADD_LINK_CONT arriving while flow->type is SMC_LLC_FLOW_REQ_ADD_LINK is stashed into flow->qentry via the SMC_LLC_CONFIRM_LINK / SMC_LLC_ADD_LINK_CONT handler (which stores into flow->qentry for any non-NONE flow type). When the subsequent ADD_LINK arrives, the REQ_ADD_LINK branch overwrites flow->qentry with the new pointer without first freeing the stashed allocation, leaking one kmalloc object.

The stashed entry has no consumer: smc_llc_wait() is only called from llc_add_link_work, which is not yet scheduled while the flow type remains REQ_ADD_LINK. No waiter is sleeping on llc_msg_waiter at this point. It is safe to unconditionally free any stashed qentry before the overwrite.

Call smc_llc_flow_qentry_del() before smc_llc_flow_qentry_set() in the REQ_ADD_LINK branch. smc_llc_flow_qentry_del() already checks flow->qentry before freeing, so the normal path where no entry is stashed is a no-op.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90108.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b4ba4652b3f8b7c9bbb5786f8acf4724bdab2196
Fixed
7dd55348c0d9399a9448847819e9f3904ae507ad
Fixed
056395acb7041b3a1f2baa08d89a1938a8b8776a
Fixed
b08aacfb226a840628151643b6a34eecf545d311
Fixed
0fb9a513766071ea9d5f3bf988e39241b8e9ee3b
Fixed
e25a602c45c76a7130878db72bcf6f76df04bf85
Fixed
036322025d6e440cb75fc6fecbba9a16b271a2ae

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90108.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90108.json"