CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's SMC (Shared Memory Communication) implementation, specifically in the handling of three connection state flags that are stored as single-bit bitfields within a single byte. This design flaw can lead to race conditions, where concurrent modifications to these flags may result in inconsistent states, potentially compromising the integrity of the connection. Organizations using Linux in environments reliant on SMC should prioritize addressing this issue to ensure robust and secure communication channels.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: net/smc: stop killed, freed and out_of_sync sharing a byte The three connection state flags are single-bit bitfields, so they occupy one byte of struct smc_connection and every store to one is a read-modify-write of the other two: u8 killed : 1; u8 freed : 1; u8 out_of_sync : 1; They are not written under a common lock. smc_cdc_msg_validate() sets out_of_sync from the receive tasklet, while smc_conn_kill() sets killed from process context under lock_sock(), and the receive path does not defer to the backlog when the socket is owned -- smc_cdc_msg_recv() takes only bh_lock_sock(). Give each flag its own byte so a store no longer touches its neighbours. All readers test them as booleans and are unchanged. struct smc_connection grows by two bytes.