Use-after-free in Linux kernel - CVE-2026-46330
Published: June 10, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in the SMC TCP ULP support in net/smc/af_smc.c when converting an active TCP socket into an SMC socket by modifying open-file VFS structures in place. A local user can trigger the flawed socket conversion to cause a denial of service.
The issue stems from in-place modification of struct file, dentry, and inode objects that are expected to remain immutable for an open file.