In the Linux kernel, the following vulnerability has been resolved: net: smc: fix splice entry lifetime imbalance in smc_rx_splice smc_rx_splice()… (CVE-2026-74631)
A use-after-free vulnerability in the Linux kernel's SMC (Shared Memory Communications) network subsystem was fixed. The flaw involved a reference count imbalance in the smc_rx_splice() function, where page and socket references were not properly managed before passing pages to splice_to_pipe(). This could lead to underflow of page reference counts and potential use-after-free conditions.
AI Analysis
Technical Summary
The vulnerability in the Linux kernel's SMC network code arises from improper reference counting in the smc_rx_splice() function. Specifically, pages are passed to splice_to_pipe() before taking the necessary references that cover the lifetime of each splice entry. In the VM-backed RMB path, splice_to_pipe() may drop unqueued entries prematurely, while queued entries are released later via pipe buffer callbacks. The previous accounting method derived the number of queued VM pages from a mutated offset and paired one sock_hold() with multiple sock_put() calls, causing a reference count imbalance. The fix involves taking page and socket references for every candidate entry before splice_to_pipe() and adjusting the release logic to prevent underflow of page reference counts and eliminate use-after-free risks.
Potential Impact
This vulnerability can cause a use-after-free condition in the Linux kernel's SMC network subsystem, potentially leading to memory corruption or kernel instability. However, no known exploits in the wild have been reported. The impact is limited to systems using the affected SMC code path.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to correct the reference counting imbalance in smc_rx_splice(). Users should apply the official kernel updates that include this fix. Since no patch links or vendor advisories are provided here, check the Linux kernel mailing lists or official kernel repositories for the relevant patch and update instructions. Patch status is not yet confirmed in this data — verify with vendor sources for current remediation guidance.
In the Linux kernel, the following vulnerability has been resolved: net: smc: fix splice entry lifetime imbalance in smc_rx_splice smc_rx_splice()… (CVE-2026-74631)
Description
A use-after-free vulnerability in the Linux kernel's SMC (Shared Memory Communications) network subsystem was fixed. The flaw involved a reference count imbalance in the smc_rx_splice() function, where page and socket references were not properly managed before passing pages to splice_to_pipe(). This could lead to underflow of page reference counts and potential use-after-free conditions.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in the Linux kernel's SMC network code arises from improper reference counting in the smc_rx_splice() function. Specifically, pages are passed to splice_to_pipe() before taking the necessary references that cover the lifetime of each splice entry. In the VM-backed RMB path, splice_to_pipe() may drop unqueued entries prematurely, while queued entries are released later via pipe buffer callbacks. The previous accounting method derived the number of queued VM pages from a mutated offset and paired one sock_hold() with multiple sock_put() calls, causing a reference count imbalance. The fix involves taking page and socket references for every candidate entry before splice_to_pipe() and adjusting the release logic to prevent underflow of page reference counts and eliminate use-after-free risks.
Potential Impact
This vulnerability can cause a use-after-free condition in the Linux kernel's SMC network subsystem, potentially leading to memory corruption or kernel instability. However, no known exploits in the wild have been reported. The impact is limited to systems using the affected SMC code path.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to correct the reference counting imbalance in smc_rx_splice(). Users should apply the official kernel updates that include this fix. Since no patch links or vendor advisories are provided here, check the Linux kernel mailing lists or official kernel repositories for the relevant patch and update instructions. Patch status is not yet confirmed in this data — verify with vendor sources for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-75cj-q634-phhq
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-74631"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a8a27f2acd9273b499bc84a
Added to database: 08/22/2026, 22:51:30 UTC
Last enriched: 08/22/2026, 23:39:46 UTC
Last updated: 08/23/2026, 00:12:09 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.