Skip to content
CVSS 9.8 · CRITICAL

CVE-2026-45972

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF and double free in smb2_open_file() Zero out @err_iov and @err_buftype before retrying SMB2_open() to prevent an UAF bug if @data != NULL, otherwise a double free.

View on NVD

Analysis

A critical vulnerability has been identified in the Linux kernel SMB client (CIFS) that could lead to a Use-After-Free or double-free condition. This flaw potentially allows for kernel-level compromise or a system crash if the system connects to a malicious SMB share. Users should update their Linux kernels to the latest patched version.

Severity

Score: 9.8(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH

EPSS

Probability of exploitation (next 30 days): 0.0006 (0.1%)
Percentile: 17.4%
EPSS: 2026-05-30

Technical description

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF and double free in smb2_open_file() Zero out @err_iov and @err_buftype before retrying SMB2_open() to prevent an UAF bug if @data != NULL, otherwise a double free.

Published: 5/27/2026, 2:17:14 PM
Last modified: 5/30/2026, 11:17:17 AM

References

HomeEventsBlogResourcesTeam