Skip to content
CVSS 9.8 · CRITICAL

CVE-2026-64597Double-free in Linux kernel SMB client

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_close_init() fails before the next send, cleanup retains the previous buffer type and frees that response again. Reset response bookkeeping before each attempt to prevent the stale free.

View on NVD

Analysis

A double-free vulnerability in the Linux kernel SMB client could allow a malicious server to execute code or crash the client system. This is a critical risk for Linux servers and workstations that mount remote SMB/CIFS file shares.

Relevant roles

LinuxBackendDockerCloudCyberSecurityKubernetes

Severity

Score: 9.8(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH

EPSS

Probability of exploitation (next 30 days): 0.0016 (0.2%)
Percentile: 5.3%
EPSS: 2026-08-08

Technical description

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_close_init() fails before the next send, cleanup retains the previous buffer type and frees that response again. Reset response bookkeeping before each attempt to prevent the stale free.

Published: 8/6/2026, 8:16:35 AM
Last modified: 8/8/2026, 3:16:34 PM

References

HomeEventsBlogResourcesCoursesTeam