{"id":"CVE-2026-80985","title":"kernel: net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry (CVE-2026-80985)","summary":"A flaw was found in the Linux kernel's Server Message Block over Remote Direct Memory Access (SMC-Rv2) protocol implementation. The `smc_llc_rmt_delete_rkey()` and `smc_llc_save_add_link_rkeys()` functions incorrectly handle oversized LLC …","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-125","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 10","enterprise_linux 9","openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-14","sourceUpdated":"2026-09-14T19:34:14+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80985.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80985.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-80985"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532279"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-80985"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80985"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-80985.mbox"},{"url":"https://git.kernel.org/stable/c/0d6f80be8ac5886842640d6526abf3f9a215be75"},{"url":"https://git.kernel.org/stable/c/8d3c1ab82c11d4fadebf817a825fd221b3e197ea"},{"url":"https://git.kernel.org/stable/c/edf30d65e3ac52f886f7d87b1a7449742e79157d"}],"tags":["csaf","vex","red-hat","cve.org","score-dispute"],"epss":0.00518,"epssPercentile":0.42897,"scores":{"vendor":5.7,"cna":8.2},"ingestedAt":"2026-09-14T15:23:07.476Z","slug":"CVE-2026-80985","body":"## Overview\n\nA flaw was found in the Linux kernel's Server Message Block over Remote Direct Memory Access (SMC-Rv2) protocol implementation. The `smc_llc_rmt_delete_rkey()` and `smc_llc_save_add_link_rkeys()` functions incorrectly handle oversized LLC messages, reading beyond the intended message boundaries. This can lead to the processing of stale or unintended data from previous messages, potentially resulting in information disclosure or data corruption. A remote attacker could exploit this vulnerability to gain access to sensitive information or cause system instability.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80985.json)\n\n**kernel: net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry** — rated Important by Red Hat. Released 2026-09-11, updated 2026-09-14.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNot affected:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nAffected","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":204167,"id":"CVE-2026-80985","ts":1789490235364,"field":"cvss","old":"5.7","new":"7"},{"seq":204166,"id":"CVE-2026-80985","ts":1789490235364,"field":"severity","old":"medium","new":"high"},{"seq":202935,"id":"CVE-2026-80985","ts":1789403733016,"field":"cvss","old":"8.2","new":"5.7"},{"seq":202934,"id":"CVE-2026-80985","ts":1789403733016,"field":"severity","old":"high","new":"medium"},{"seq":183590,"id":"CVE-2026-80985","ts":1789356676010,"field":"cvss","old":"8.2","new":"5.7"},{"seq":183589,"id":"CVE-2026-80985","ts":1789356676010,"field":"severity","old":"high","new":"medium"},{"seq":153170,"id":"CVE-2026-80985","ts":1789285349390,"field":"cvss","old":null,"new":"8.2"},{"seq":153169,"id":"CVE-2026-80985","ts":1789285349390,"field":"severity","old":"none","new":"high"},{"seq":147444,"id":"CVE-2026-80985","ts":1789270210933,"field":"cvss","old":null,"new":"5.7"},{"seq":147443,"id":"CVE-2026-80985","ts":1789270210933,"field":"severity","old":"none","new":"medium"},{"seq":109200,"id":"CVE-2026-80985","ts":1789183730701,"field":"cvss","old":null,"new":"5.7"},{"seq":109199,"id":"CVE-2026-80985","ts":1789183730701,"field":"severity","old":"none","new":"medium"}]}