CVE-2026-64597

Summary

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix double-free in SMB2_close() replay

A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_close_init() fails before the next send, cleanup retains the previous buffer type and frees that response again.

Reset response bookkeeping before each attempt to prevent the stale free.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux433042a91f9373241307725b52de573933ffedbf < 037511726228aaf165c7067ff2bfc88eaecdf1f3affected
LinuxLinux4f1fffa2376922f3d1d506e49c0fd445b023a28e < 0aa97edf7c347c0f54e7e60c4740574b8120c66aaffected
LinuxLinux4f1fffa2376922f3d1d506e49c0fd445b023a28e < d15d83125007f673aec4323e1bbbaaffbe87ea13affected
LinuxLinux4f1fffa2376922f3d1d506e49c0fd445b023a28e < b18ed621dbfceecea5539848cddcb9272c9a61e1affected
LinuxLinux4f1fffa2376922f3d1d506e49c0fd445b023a28e < f96e1cdcb63ed3321142ff2fcdf784e32cda8feeaffected
LinuxLinux6.6.32 < 6.6.145affected
LinuxLinux6.8affected
LinuxLinux0 < 6.8unaffected
LinuxLinux6.6.145 <= 6.6.*unaffected
LinuxLinux6.12.96 <= 6.12.*unaffected
LinuxLinux6.18.39 <= 6.18.*unaffected
LinuxLinux7.1.4 <= 7.1.*unaffected
LinuxLinux7.2-rc1 <= *unaffected

Weaknesses

References