PT-2024-2085 · Linux+10 · Linux Kernel+10

Wen Gu

·

Published

2024-01-19

·

Updated

2025-09-29

·

CVE-2024-26615

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions 6.7.0 and earlier
Description A crash was found when dumping SMC-D connections in the Linux kernel. The issue can be reproduced by running a specific test and continuously dumping SMC-D connections in parallel. The crash is caused by a kernel NULL pointer dereference, which occurs when the connection is in the process of being established and the rmb desc has not yet been initialized. The vulnerability can be exploited to cause a denial of service.
Recommendations To resolve the issue, update the Linux kernel to a version that includes the fix for the net/smc: fix illegal rmb desc access in SMC-D connection dump vulnerability. As a temporary workaround, consider disabling the smc diag dump() function until a patch is available.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:10939
ALSA-2024:3618
ALSA-2024:3627
ALSA-2024_10939
ALSA-2025_16880
ALT-PU-2024-3457
BDU:2024-01981
CESA-2024_3618
CESA-2024_3627
CVE-2024-26615
DLA-3840-1
DLA-3842-1
DSA-5681-1
INFSA-2024_10939
INFSA-2024_3618
INFSA-2024_3627
OESA-2024-1496
OESA-2024-1497
OESA-2024-1498
OESA-2024-1499
OESA-2024-1500
OESA-2024-1501
OPENSUSE-SU-2024_2947-1
RHSA-2024:10771
RHSA-2024:10939
RHSA-2024:3618
RHSA-2024:3627
RHSA-2024_10939
RHSA-2024_3618
RHSA-2024_3627
RLSA-2024:3618
RLSA-2024:3627
SUSE-SU-2024:2802-1
SUSE-SU-2024:2892-1
SUSE-SU-2024:2894-1
SUSE-SU-2024:2896-1
SUSE-SU-2024:2901-1
SUSE-SU-2024:2939-1
SUSE-SU-2024:2940-1
SUSE-SU-2024:2947-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
USN-6765-1
USN-6766-1
USN-6766-2
USN-6766-3
USN-6767-1
USN-6767-2
USN-6795-1
USN-6818-1
USN-6818-2
USN-6818-3
USN-6818-4
USN-6819-1
USN-6819-2
USN-6819-3
USN-6819-4
USN-6828-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu