External risk intelligence

Linux Kernel SMC-Rv2 Out-of-Bounds Read Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-80986

The vulnerability exists within the Linux kernel's SMC (Shared Memory Communications) protocol implementation. This is a low-level kernel networking subsystem used for internal host-to-host or inter-process communication, not an internet-facing service or application. It is not exposed to the public internet in normal deployments.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a flaw in the Linux kernel's networking component that could allow unauthorized access and modification of data. While resolved, its relevance depends on specific network configurations and usage patterns within your environment. The primary concern is to confirm if this specific kernel functionality is in use and exposed.

  • Kernel flaw may allow unauthorized data access.
  • Confirm usage of specific networking features.
  • Assess internal exposure and potential impact.

Attack Path

How an attacker could exploit the issue

An attacker could leverage this vulnerability by establishing a link with a specially crafted message that exploits how the Linux kernel handles shared memory communications (SMC) protocol version 2. If a specific network link configuration exists, sending this malformed message could lead to a kernel crash or potentially more severe system compromise.

  • Requires network access to a vulnerable system.
  • Triggered by sending a malformed SMC-Rv2 message.
  • Can lead to a kernel crash or system compromise.

Live Threat

Current exploitation, exposure, and threat context

The Linux kernel's Shared Memory Communications (SMC) protocol, specifically its v2 implementation for link establishment, could be vulnerable when a device has `max_recv_sge` set to 1. This scenario lacks shared v2 receive buffers, potentially leading to out-of-bounds read operations during link addition. The affected memory access happens when processing peer-sent `SMC-Rv2 LLC` messages.

  • Kernel memory access could be read.
  • Incorrect message processing may trigger it.
  • System stability may be impacted.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the Linux kernel's Shared Memory Communications (SMC) protocol affects networking infrastructure. The Linux kernel team is responsible for addressing this issue. The first practical step is to identify all Linux systems utilizing the SMC protocol, confirm their exposure and criticality, and then plan remediation with the Linux kernel development or maintenance team.

  • Kernel development teams should own this issue.
  • Verify SMC protocol usage and network exposure.
  • Plan kernel updates during maintenance windows.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Linux kernel SMC protocol?

SMC (Shared Memory Communications) is a networking subsystem in the Linux kernel designed to accelerate data transfer by allowing systems to use shared memory instead of traditional TCP/IP stacks. It is typically used for high-performance host-to-host or inter-process communication within internal data center environments to reduce latency.

What kind of vulnerability is CVE-2026-80986?

This is an out-of-bounds read vulnerability. It occurs when the kernel incorrectly calculates the memory location of data within an incoming SMC-Rv2 Link Layer Control (LLC) message. Because the system attempts to read information from an invalid memory address during the link addition process, it can trigger a kernel crash or other unpredictable behavior.

How is this vulnerability triggered?

The issue is triggered when a system with a specific configuration—where the device's maximum receive scatter-gather elements (max_recv_sge) is set to 1—processes a specially crafted SMC-Rv2 link addition message from a peer. It does not trigger if the SMC-Rv2 feature is disabled or if the system configuration does not meet this specific link parameter requirement.

Is my system at risk from the internet?

According to Halo Surface Signal, this vulnerability affects low-level kernel networking code not typically exposed to the public internet. While the CVSS score is high, the protocol is generally used for internal communication, making it very unlikely to be reachable from an external-facing network position in a standard deployment.

What should I do to address this?

First, verify if your Linux systems have the SMC protocol enabled and if they are configured to use SMC-Rv2. If these features are in use, prioritize reviewing your kernel version and coordinate with your maintenance team to apply the necessary kernel updates or patches provided by your distribution vendor during a scheduled maintenance window.

References