Out-of-bounds read in Linux kernel - CVE-2026-80986
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in smc_llc_save_add_link_rkeys() when processing SMC-Rv2 link additions. A remote attacker can initiate an SMC-Rv2 link addition to cause a denial of service.
The issue occurs on links whose device has max_recv_sge set to 1, where no shared version 2 receive buffer is available.