CVE-2024-56640·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: net/smc: fix LGR and link use-after-free issue We encountered a LGR/link use-after-free issue, which manifested as the LGR/link refcnt reaching 0 early and entering the clear process, making resource access unsafe. refcount_t: addition on 0; use-after-free. WARNING: CPU: 14 PID: 107447 at lib/refcount.c:25 refcount_warn_saturate+0x9c/0x140 Workqueue: events smc_lgr_terminate_work [smc] Call trace: refcount_warn_saturate+0x9c/0x140 __smc_lgr_terminate.part.45+0x2a8/0x370 [smc] smc_lgr_terminate_work+0x28/0x30 [smc] process_one_work+0x1b8/0x420 worker_thread+0x158/0x510 kthread+0x114/0x118 or refcount_t: underflow; use-after-free. WARNING: CPU: 6 PID: 93140 at lib/refcount.c:28 refcount_warn_saturate+0xf0/0x140 Workqueue: smc_hs_wq smc_listen_work [smc] Call trace: refcount_warn_saturate+0xf0/0x140 smcr_link_put+0x1cc/0x1d8 [smc] smc_conn_free+0x110/0x1b0 [smc] smc_conn_abort+0x50/0x60 [smc] smc_listen_find_device+0x75c/0x790 [smc] smc_listen_work+0x368/0x8a0 [smc] process_one_work+0x1b8/0x420 worker_thread+0x158/0x510 kthread+0x114/0x118 It is caused by repeated release of LGR/link refcnt. One suspect is that smc_conn_free() is called repeatedly because some smc_conn_free() from server listening path are not protected by sock lock. e.g. Calls under socklock | smc_listen_work ------------------------------------------------------- lock_sock(sk) | smc_conn_abort smc_conn_free | \- smc_conn_free \- smcr_link_put | \- smcr_link_put (duplicated) release_sock(sk) So here add sock lock protection in smc_listen_work() path, making it exclusive with other connection operations.
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.12.5
- Published
- 2024-12-27
Affected versions
From: 6.7
Until: 6.12.5
Fixed in: 6.12.5
How to fix this CVE
Update your Linux kernel to version 6.12.5 or later to resolve a critical use-after-free vulnerability in the SMC (Shared Memory Communications) subsystem. This bug causes reference counting errors when the listener path improperly releases connection and link resources without proper socket locking, leading to premature resource deallocation and kernel warnings. Systems running kernel versions 6.7 through 6.12.4 should prioritize this update to prevent potential system instability.
sudo dnf update kernel kernel-develDefensia detects this vulnerability
How to check if you are affected
- Check installed kernel version: uname -r
- Verify if SMC (RDMA over Converged Ethernet) is in use: lsmod | grep smc
- Search kernel logs for refcount warnings: sudo journalctl -b | grep -i 'refcount\|use-after-free'
- Confirm patch status: grep -i 'CONFIG_SMC' /boot/config-$(uname -r) and verify kernel version is 6.12.5 or later
FAQ
What is CVE-2024-56640?
This vulnerability is a use-after-free bug in the Linux kernel's SMC networking driver where the listener connection establishment path fails to acquire socket locks before releasing connection resources, allowing duplicate reference count decrements that cause the kernel to access freed memory.
Is CVE-2024-56640 being actively exploited?
No, this vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploits are currently available, though it can cause kernel instability if triggered.
What versions of Kernel are affected by CVE-2024-56640?
Linux kernel versions 6.7 through 6.12.4 are vulnerable; version 6.12.5 and later contain the fix.
How do I check if my server is vulnerable to CVE-2024-56640?
Run `uname -r` to check your kernel version—if it shows 6.7.x through 6.12.4, your system is vulnerable. Additionally, verify SMC is compiled in with `grep CONFIG_SMC /boot/config-$(uname -r)`.
Does Defensia detect CVE-2024-56640?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2024-56640 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/0cf598548a6c36d90681d53c6b77d52363f2f295
- https://git.kernel.org/stable/c/2c7f14ed9c19ec0f149479d1c2842ec1f9bf76d7
- https://git.kernel.org/stable/c/673d606683ac70bc074ca6676b938bff18635226
- https://git.kernel.org/stable/c/6f0ae06a234a78ae137064f2c89135ac078a00eb
- https://git.kernel.org/stable/c/f502a88fdd415647a1f2dc45fac71b9c522a052b
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-56640. Free for 1 server.
Get started free