CVE-2024-47408
A vulnerability in the Linux kernel's SMC (Scalable Service Architecture) component allows a remote client to send a malicious message that can cause the system to crash. This happens because the system fails to properly validate certain data received from the client.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users running Linux kernel version 6.13 or later that utilize the net/smc component.
Real-world impact
An attacker could remotely trigger a system crash, leading to a denial of service (DoS) on the affected machine.
Why this severity
The score is critical because the vulnerability can be exploited remotely without any user interaction or authentication, and it can lead to a complete loss of system availability.
What to do about it
- 01Apply the patch that validates the smcd_v2_ext_offset value in the Linux kernel.
NVD-referenced vendor advisory
Timeline
- Jan 11, 2025 · Jan 11, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 4, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.