CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-74692

highCVSS 7.5covered by 2 sourcesfirst seen 2026-08-11
In the Linux kernel, the following vulnerability has been resolved: net/smc: fix TOCTOU race between smc_listen_out() and listener close smc_listen_out() reads lsmc->sk.sk_state without the listener lock, then acquires lock_sock_nested() only after the check passes. This opens a window where smc_close_active() can transition the listener to SMC_CLOSED, call smc_close_cleanup_listen() to drain the accept queue, and release the lock, all between the lockless read and the delayed lock acquisition: smc_listen_work (smc_hs_wq) smc_close_active() ------------------------------- ------------------------- release_sock(child) if (sk_state == SMC_LISTEN) TRUE lock_sock(listener) sk_state = SMC_CLOSED smc_close_cleanup_listen() release_sock(listener) flush_work(tcp_listen_work) lock_sock_nested(listener) smc_accept_enqueue(listener, child) /* child enqueued on dead listener */ smc_close_active() flushes only tcp_listen_work. Work items already dispatched onto smc_hs_wq for the CLC handshake continue running unguarded. smc_accept_enqueue() takes a sock_hold() on the child that is never released, so the child smc_sock, its clcsock, and the reference all leak. A remote peer that opens TCP connections while the server calls close() can exhaust kernel memory. Move lock_sock_nested() to before the sk_state check so that the test and the enqueue are atomic under the listener lock.

CSIRTS triage

What
SMC (Shared Memory Communications) has a TOCTOU race condition between smc_listen_out() and listener socket close, leading to use-after-free.
Who is affected
Systems using SMC protocol for low-latency communication with concurrent listening and close operations.
Urgency
Medium priority; CVSS 5.9 indicates moderate severity; not currently exploited but race condition can cause crashes.
Action
Apply kernel patch serializing smc_listen_out() and listener close operations or update to patched version.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-74692

Get an email if CVE-2026-74692 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-74692

CVE.org record

Embed the live status

CVE-2026-74692 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-74692 status](https://www.csirts.com/badge/CVE-2026-74692)](https://www.csirts.com/cve/CVE-2026-74692)