# CVE-2026-80979

## Summary

- **CVE ID:** CVE-2026-80979
- **Severity:** HIGH
- **CVSS Score:** 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 14, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

net/smc: unregister the connection before draining the rx tasklet

smc_conn_free() calls smc_ism_unset_conn() only while the link group is
still on its device list, and never sets conn->killed.
smc_lgr_terminate_sched() unlinks the group immediately and defers killing
its connections to a work item, so a connection freed in that window keeps
its smcd->conn[] slot with both gates in smcd_handle_irq() open, and the
device can re-arm the receive tasklet after tasklet_kill() has returned. On
the DMB-nocopy path the ghost send buffer is freed right after that drain,
so the re-armed tasklet dereferences it.

Unregister unconditionally and drain before the detach at both teardown
sites, mirroring rmb_desc, which smc_buf_unuse() releases after the drain.
Clear conn->sndbuf_desc before freeing it as well, so a reader that samples
the pointer cannot get one that is already freed.

## Affected Products

- Linux — Linux (ae2be35cbed2c8385e890147ea321a3fcc3ca5fa)
- Linux — Linux (21f6f41e82e59740e26e06e77bdf58dc7f6f08dd)
- Linux — Linux (6.6.66)
- Linux — Linux (6.10)
- Linux — Linux (0)
- Linux — Linux (6.12.109)
- Linux — Linux (6.18.50)
- Linux — Linux (7.2.4)
- Linux — Linux (7.3-rc1)
- Linux — Linux (6.6.157)

## References

- [CNA](https://git.kernel.org/stable/c/b4d540ac95cd35c6ebab6afb7eae2bcac7b277a5)
- [CNA](https://git.kernel.org/stable/c/5bd8b764a610b6b6bc0c4d3d01652747f6e0b5c3)
- [CNA](https://git.kernel.org/stable/c/b74d313567dfc1b7e56629ddbad04e728686f235)
- [CNA](https://git.kernel.org/stable/c/36cdf5d48ca191dcd71c28cadbe0981b1d25318d)
- [CNA](https://git.kernel.org/stable/c/b6b6ac713ee82b340a8e3be30b101bd2840deec4)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.13%
- **EPSS Percentile:** 2.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._