{"apiVersion":"1.0","identifier":"CVE-2026-74493","description":"In the Linux kernel, the following vulnerability has been resolved: net/smc: fix socket use-after-free during link group termination __smc_lgr_terminate() drops conns_lock after finding a connection in lgr->conns_all, but before taking a reference on its socket. The connection is embedded in the socket, and its registration reference protects it only while the connection remains in the tree. A concurrent close can unregister the connection and drop that reference, freeing the socket before the termination worker reaches sock_hold(). The race is reachable when close overlaps link group termination. Local stress testing reproduced the use-after-free and KASAN reported: BUG: KASAN: slab-use-after-free in __smc_lgr_terminate.part.0 [smc] Write of size 4 by task kworker/3:3 Workqueue: events smc_lgr_terminate_work [smc] __smc_lgr_terminate.part.0 [smc] The socket was allocated by smc_create(), freed through slab_free_after_rcu_debug(), and was followed by: refcount_t: addition on 0; use-after-free. __smc_lgr_terminate.part.0 [smc] Take the socket reference while conns_lock still protects the tree entry. The unregister path then cannot drop the last reference until termination has finished using the socket.","publishedAt":"2026-08-15T13:17:54","lastModifiedAt":"2026-08-19T17:21:06","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-74493","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","epssProbability":0.005,"riskScore":1.02,"affectedProduct":"linux","affectedVersions":"unknown","vulnerabilityType":"Kernel","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-74493","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-74493","en":"https://www.redsauce.net/en/cves/CVE-2026-74493","fr":"https://www.redsauce.net/fr/cves/CVE-2026-74493","pt":"https://www.redsauce.net/pt/cves/CVE-2026-74493","de":"https://www.redsauce.net/de/cves/CVE-2026-74493","sk":"https://www.redsauce.net/sk/cves/CVE-2026-74493","el":"https://www.redsauce.net/el/cves/CVE-2026-74493"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-74493"}}