CVE-2026-64386

Summary

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix query_info() replay double-free

A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_query_info_init() fails before the next send, cleanup retains the previous buffer type and frees that response again.

Reset response bookkeeping before each attempt to prevent the stale free.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux433042a91f9373241307725b52de573933ffedbf < 100fb7c455fa86d248b8bd7bb9de757c192870b4affected
LinuxLinux4f1fffa2376922f3d1d506e49c0fd445b023a28e < 3c81dda84799f76b42aec598564316e2964440dbaffected
LinuxLinux4f1fffa2376922f3d1d506e49c0fd445b023a28e < f1add4acb656f5a82806a1ab0e63fed3d8b1bfcaaffected
LinuxLinux4f1fffa2376922f3d1d506e49c0fd445b023a28e < 89234773e8348918111aa15f6922b58cf3843364affected
LinuxLinux4f1fffa2376922f3d1d506e49c0fd445b023a28e < 2a88561d66eb855813cf004a0abe648bbb17de5eaffected
LinuxLinux6.6.32 < 6.6.145affected
LinuxLinux6.8affected
LinuxLinux0 < 6.8unaffected
LinuxLinux6.6.145 <= 6.6.*unaffected
LinuxLinux6.12.96 <= 6.12.*unaffected
LinuxLinux6.18.39 <= 6.18.*unaffected
LinuxLinux7.1.4 <= 7.1.*unaffected
LinuxLinux7.2-rc1 <= *unaffected

Weaknesses

References