---
id: CVE-2024-47408
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  net/smc: check smcd_v2_ext_offset when receiving proposal msg

  When receiving proposal msg in server, the field smcd_v2_ext_offset in
  proposal msg is from the remote cl…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  net/smc: check smcd_v2_ext_offset when receiving proposal msg

  When receiving proposal msg in server, the field smcd_v2_ext_offset in
  proposal msg is from the remote cl…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 5.10, < 5.15.176'
  - 'linux_kernel >= 5.16, < 6.1.122'
  - 'linux_kernel >= 6.2, < 6.6.68'
  - 'linux_kernel >= 6.7, < 6.12.7'
  - linux_kernel = 6.13
patched:
  - linux_kernel 6.12.7
published: '2025-01-11'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T11:17:31.323'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-47408'
references:
  - url: 'https://git.kernel.org/stable/c/35da53027c1f2efdd7d0177dc00584134204761a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/48d5a8a304a643613dab376a278f29d3e22f7c34'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/935caf324b445fe73d7708fae6f7176fb243f357'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9ab332deb671d8f7e66d82a2ff2b3f715bc3a4ad'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a36364d8d4fabb105001f992fb8ff2d3546203d6'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e1cc8be2a785a8f1ce1f597f3e608602c5fccd46'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
epss: 0.00625
epssPercentile: 0.48104
ingestedAt: '2026-10-03T11:43:42.105Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

net/smc: check smcd_v2_ext_offset when receiving proposal msg

When receiving proposal msg in server, the field smcd_v2_ext_offset in
proposal msg is from the remote client and can not be fully trusted.
Once the value of smcd_v2_ext_offset exceed the max value, there has
the chance to access wrong address, and crash may happen.

This patch checks the value of smcd_v2_ext_offset before using it.

## Affected

- `linux_kernel >= 5.10, < 5.15.176`
- `linux_kernel >= 5.16, < 6.1.122`
- `linux_kernel >= 6.2, < 6.6.68`
- `linux_kernel >= 6.7, < 6.12.7`
- `linux_kernel = 6.13`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.12.7`
