Home

Description

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix one NULL pointer dereference in smc_ib_is_sg_need_sync() BUG: kernel NULL pointer dereference, address: 00000000000002ec PGD 0 P4D 0 Oops: Oops: 0000 [#1] SMP PTI CPU: 28 UID: 0 PID: 343 Comm: kworker/28:1 Kdump: loaded Tainted: G OE 6.17.0-rc2+ #9 NONE Tainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODULE Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.15.0-1 04/01/2014 Workqueue: smc_hs_wq smc_listen_work [smc] RIP: 0010:smc_ib_is_sg_need_sync+0x9e/0xd0 [smc] ... Call Trace: <TASK> smcr_buf_map_link+0x211/0x2a0 [smc] __smc_buf_create+0x522/0x970 [smc] smc_buf_create+0x3a/0x110 [smc] smc_find_rdma_v2_device_serv+0x18f/0x240 [smc] ? smc_vlan_by_tcpsk+0x7e/0xe0 [smc] smc_listen_find_device+0x1dd/0x2b0 [smc] smc_listen_work+0x30f/0x580 [smc] process_one_work+0x18c/0x340 worker_thread+0x242/0x360 kthread+0xe7/0x220 ret_from_fork+0x13a/0x160 ret_from_fork_asm+0x1a/0x30 </TASK> If the software RoCE device is used, ibdev->dma_device is a null pointer. As a result, the problem occurs. Null pointer detection is added to prevent problems.

PUBLISHED Reserved 2025-04-16 | Published 2025-09-19 | Updated 2025-11-03 | Assigner Linux

Product status

Default status
unaffected

0ef69e788411cba2af017db731a9fc62d255e9ac (git) before 0cdf1fd8fc59d44a48c694324611136910301ef9
affected

0ef69e788411cba2af017db731a9fc62d255e9ac (git) before f18d9b3abf9c6587372cc702f963a7592277ed56
affected

0ef69e788411cba2af017db731a9fc62d255e9ac (git) before eb929910bd4b4165920fa06a87b22cc6cae92e0e
affected

0ef69e788411cba2af017db731a9fc62d255e9ac (git) before 34f17cbe027050b8d5316ea1b6f9bd7c378e92de
affected

0ef69e788411cba2af017db731a9fc62d255e9ac (git) before ba1e9421cf1a8369d25c3832439702a015d6b5f9
affected

Default status
affected

6.0
affected

Any version before 6.0
unaffected

6.1.151 (semver)
unaffected

6.6.105 (semver)
unaffected

6.12.46 (semver)
unaffected

6.16.6 (semver)
unaffected

6.17 (original_commit_for_fix)
unaffected

References

lists.debian.org/debian-lts-announce/2025/10/msg00008.html

git.kernel.org/...c/0cdf1fd8fc59d44a48c694324611136910301ef9

git.kernel.org/...c/f18d9b3abf9c6587372cc702f963a7592277ed56

git.kernel.org/...c/eb929910bd4b4165920fa06a87b22cc6cae92e0e

git.kernel.org/...c/34f17cbe027050b8d5316ea1b6f9bd7c378e92de

git.kernel.org/...c/ba1e9421cf1a8369d25c3832439702a015d6b5f9

cve.org (CVE-2025-39857)

nvd.nist.gov (CVE-2025-39857)

Download JSON