CVE-2026-64385

Summary

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix double-free in SMB2_ioctl() replay

A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_ioctl_init() fails before the next send, cleanup retains the previous buffer type and frees that response again.

Reset response bookkeeping before each attempt to prevent the stale free.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux433042a91f9373241307725b52de573933ffedbf < 0be4bc64882edaefaaee8d1e27d083643eb778e6affected
LinuxLinux4f1fffa2376922f3d1d506e49c0fd445b023a28e < 96fcfc8ae7359346156e492ca610e830d2649ad6affected
LinuxLinux4f1fffa2376922f3d1d506e49c0fd445b023a28e < 276c8efbc49f9303ac76d0d4deab7128581b0f3baffected
LinuxLinux4f1fffa2376922f3d1d506e49c0fd445b023a28e < fc65ffb4ef1bf540da16b17c225ae51091e07d72affected
LinuxLinux4f1fffa2376922f3d1d506e49c0fd445b023a28e < f9bbadb6c94583e3b4af1afc449bfceb1d1ddec9affected
LinuxLinux6.6.32 < 6.6.145affected
LinuxLinux6.8affected
LinuxLinux0 < 6.8unaffected
LinuxLinux6.6.145 <= 6.6.*unaffected
LinuxLinux6.12.96 <= 6.12.*unaffected
LinuxLinux6.18.39 <= 6.18.*unaffected
LinuxLinux7.1.4 <= 7.1.*unaffected
LinuxLinux7.2-rc1 <= *unaffected

Weaknesses

References