CVE-2026-64597

CRITICAL

smb: client: fix double-free in SMB2_close() replay

Title source: cna
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_close_init() fails before the next send, cleanup retains the previous buffer type and frees that response again. Reset response bookkeeping before each attempt to prevent the stale free.

Scores

CVSS v3 9.8
EPSS 0.0036
EPSS Percentile 29.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (17)
linux/Kernel < 6.6.145linux
linux/Kernel 6.13.0 - 7.1.4linux
linux/Kernel 6.7.0 - 6.12.96linux
linux/Kernel 6.8.0 - 6.18.39linux
Linux/Linux < 6.8
Linux/Linux 433042a91f9373241307725b52de573933ffedbf - 037511726228aaf165c7067ff2bfc88eaecdf1f3
Linux/Linux 4f1fffa2376922f3d1d506e49c0fd445b023a28e - 0aa97edf7c347c0f54e7e60c4740574b8120c66a
Linux/Linux 4f1fffa2376922f3d1d506e49c0fd445b023a28e - b18ed621dbfceecea5539848cddcb9272c9a61e1
Linux/Linux 4f1fffa2376922f3d1d506e49c0fd445b023a28e - d15d83125007f673aec4323e1bbbaaffbe87ea13
Linux/Linux 4f1fffa2376922f3d1d506e49c0fd445b023a28e - f96e1cdcb63ed3321142ff2fcdf784e32cda8fee
... and 7 more
Published Aug 06, 2026
Tracked Since Aug 06, 2026