SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-64382

HIGH · CVSS 8.8 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published 2026-07-25 · Last synced 2026-08-24

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's SMB2 client implementation, specifically in the SMB2_open() function, where a double-free condition can occur due to improper handling of response buffers. This flaw could lead to memory corruption, potentially allowing an attacker to execute arbitrary code or crash the system. Organizations using Linux systems that rely on SMB2 for file sharing should prioritize patching this vulnerability to mitigate the associated risks.

CVE
CVE-2026-64382
Severity
HIGH
CVSS
8.8
EPSS
0.35%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_open() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_open_init() fails before the next send, cleanup retains the previous buffer type and frees that response again. Reset response bookkeeping before each attempt to prevent the stale free.