CVE-2026-80985High· 7.0▾ TwilightA flaw was found in the Linux kernel's Server Message Block over Remote Direct Memory Access (SMC-Rv2) protocol implementation. The `smc_llc_rmt_delete_rkey()` and `smc_llc_save_add_link_rkeys()` functions incorrectly handle oversized LLC …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 38.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
— → 5.7
none → medium
0.2% → 0.5%
— → 5.7
none → medium
— → 8.2
none → high
Last analysed / modified upstream
8.2 → 5.7
high → medium
8.2 → 5.7
high → medium
5.7 → 7
medium → high
A flaw was found in the Linux kernel's Server Message Block over Remote Direct Memory Access (SMC-Rv2) protocol implementation. The smc_llc_rmt_delete_rkey() and smc_llc_save_add_link_rkeys() functions incorrectly handle oversized LLC messages, reading beyond the intended message boundaries. This can lead to the processing of stale or unintended data from previous messages, potentially resulting in information disclosure or data corruption. A remote attacker could exploit this vulnerability to gain access to sensitive information or cause system instability.
kernel: net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry — rated Important by Red Hat. Released 2026-09-11, updated 2026-09-14.
Affected:
No fix planned:
Not affected:
Affected
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-80976High· 7.0kernel: seg6: reset IP6CB after IPv6 decapsulation (CVE-2026-80976)
CVE-2026-89691High· 7.0kernel: nfsd: clear opcnt on compound arg release to prevent OOB read (CVE-2026-89691)
CVE-2026-80969Medium· 5.5kernel: ALSA: mpu401: Check card index validity at probe (CVE-2026-80969)
CVE-2026-80972Medium· 5.5kernel: ALSA: aloop: Check card index validity at probe (CVE-2026-80972)
CVE-2026-80973High· 7.0kernel: ALSA: 6fire: bound the MIDI event length from the device (CVE-2026-80973)
CVE-2026-89443Medium· 5.5kernel: platform/x86: ISST: Validate level in perf mask ioctls (CVE-2026-89443)