{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2024-36945", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2024-05-30T15:25:07.079Z", "datePublished": "2024-05-30T15:35:43.299Z", "dateUpdated": "2026-08-05T11:32:12.557Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T11:32:12.557Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: fix neighbour and rtable leak in smc_ib_find_route()\n\nIn smc_ib_find_route(), the neighbour found by neigh_lookup() and rtable\nresolved by ip_route_output_flow() are not released or put before return.\nIt may cause the refcount leak, so fix it." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:N - The leak is triggered while processing SMC CLC handshake messages received over TCP from a remote peer — the server path takes `daddr` straight from the peer's CLC Proposal v2 extension GID (`af_smc.c:2323`) and the client path from the peer's CLC Accept GID (`af_smc.c:1245`). No local access, and no RDMA fabric connectivity to the attacker is needed since the handshake is ordinary TCP.\nAC:L - The missing `neigh_release()`/`ip_rt_put()` is unconditional — every successful route resolution leaks, with no race to win and no memory-layout dependency, and the attacker fully controls `daddr` via the GID it advertises. In an SMC-Rv2 deployment (the scenario in which this code runs at all) the attacker just opens TCP connections in a loop to accumulate leaked references.\nPR:N - `smc_listen_work()` processes the CLC Proposal immediately after TCP accept, before any credential check exists — SMC has no authentication, and the UEID compared in `smc_clc_match_eid()` is a cleartext fabric identifier the client itself broadcasts in its proposal, not a secret. The client-side path via `smc_connect_rdma_v2_prepare()` requires no EID from the attacker at all.\nUI:N - The attacker initiates the TCP connection to a victim SMC listener and drives the entire handshake itself; the listen worker runs asynchronously with no action by any local user.\nS:U - The leaked `rtable`, `neighbour` and pinned `net_device` references all remain within the kernel's own resource domain, and no VM/host, IOMMU, or sandbox boundary is crossed.\nC:N - Only reference counts are leaked — no freed or out-of-bounds memory is read, and nothing from kernel memory is copied back to the peer or to userspace. `nexthop_mac` is filled from a validly-held neighbour before the leak occurs.\nI:N - The bug is a missing decrement, which is the safe direction — no object is freed early, so there is no UAF, write primitive, or control-flow impact, and both `rcuref` (dst) and `refcount_t` (neigh) saturate with a warning rather than wrapping to zero.\nA:H - Each leaked `dst` and `neighbour` permanently pins a `net_device` reference (`netdev_hold()` in `dst_init()`/`neigh_alloc()`), so device unregistration and network-namespace teardown hang forever in the `unregister_netdevice: waiting for %s to become free` loop, blocking the global `cleanup_net` worker. Additionally, `neigh_forced_gc()` skips any entry with refcount > 1, so an unauthenticated peer varying its advertised GID mints unreclaimable ARP entries until `gc_thresh3` overflow breaks all neighbour resolution on the host, alongside unbounded kernel memory growth." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "net/smc/smc_ib.c" ], "versions": [ { "version": "e5c4744cfb598f98672f8d21d59ef2c1fa9c9b5f", "lessThan": "d5a466ab6e78d6f2e0f64435f1e17246c8e941ff", "status": "affected", "versionType": "git" }, { "version": "e5c4744cfb598f98672f8d21d59ef2c1fa9c9b5f", "lessThan": "5df93c029a907b0ff5a4eeadd77ba06ff0a277d2", "status": "affected", "versionType": "git" }, { "version": "e5c4744cfb598f98672f8d21d59ef2c1fa9c9b5f", "lessThan": "da91e447d06dc649fcf46e59122e7bf8f0b2e0db", "status": "affected", "versionType": "git" }, { "version": "e5c4744cfb598f98672f8d21d59ef2c1fa9c9b5f", "lessThan": "2ddc0dd7fec86ee53b8928a5cca5fbddd4fc7c06", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "net/smc/smc_ib.c" ], "versions": [ { "version": "5.16", "status": "affected" }, { "version": "0", "lessThan": "5.16", "status": "unaffected", "versionType": "semver" }, { "version": "6.1.91", "lessThanOrEqual": "6.1.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.31", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.8.10", "lessThanOrEqual": "6.8.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.9", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.16", "versionEndExcluding": "6.1.91" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.16", "versionEndExcluding": "6.6.31" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.16", "versionEndExcluding": "6.8.10" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.16", "versionEndExcluding": "6.9" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/d5a466ab6e78d6f2e0f64435f1e17246c8e941ff" }, { "url": "https://git.kernel.org/stable/c/5df93c029a907b0ff5a4eeadd77ba06ff0a277d2" }, { "url": "https://git.kernel.org/stable/c/da91e447d06dc649fcf46e59122e7bf8f0b2e0db" }, { "url": "https://git.kernel.org/stable/c/2ddc0dd7fec86ee53b8928a5cca5fbddd4fc7c06" } ], "title": "net/smc: fix neighbour and rtable leak in smc_ib_find_route()", "x_generator": { "engine": "bippy-1.2.0" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2024-06-04T20:30:31.469457Z", "id": "CVE-2024-36945", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "ADP Container", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-06-04T20:30:45.208Z" } }, { "title": "CVE Program Container", "references": [ { "url": "https://git.kernel.org/stable/c/d5a466ab6e78d6f2e0f64435f1e17246c8e941ff", "tags": [ "x_transferred" ] }, { "url": "https://git.kernel.org/stable/c/5df93c029a907b0ff5a4eeadd77ba06ff0a277d2", "tags": [ "x_transferred" ] }, { "url": "https://git.kernel.org/stable/c/da91e447d06dc649fcf46e59122e7bf8f0b2e0db", "tags": [ "x_transferred" ] }, { "url": "https://git.kernel.org/stable/c/2ddc0dd7fec86ee53b8928a5cca5fbddd4fc7c06", "tags": [ "x_transferred" ] }, { "url": "https://security.netapp.com/advisory/ntap-20250404-0006/" } ], "providerMetadata": { "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2025-04-04T23:03:03.722Z" } } ] } }