SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-64385

CRITICAL · CVSS 9.8 EPSS 0.46%

Source: NVD + CISA KEV + EPSS · Published 2026-07-25 · Last synced 2026-08-24

CyberRota Analysis

AI-Generated

A critical vulnerability in the Linux kernel affects the SMB2_ioctl function, where a double-free error can occur due to improper handling of response buffers during error conditions. This flaw could lead to potential memory corruption, enabling attackers to execute arbitrary code or crash the system. Organizations utilizing Linux systems, particularly those relying on SMB protocol for file sharing, should prioritize patching this vulnerability to mitigate the associated risks.

CVE
CVE-2026-64385
Severity
CRITICAL
CVSS
9.8
EPSS
0.46%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_ioctl() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_ioctl_init() fails before the next send, cleanup retains the previous buffer type and frees that response again. Reset response bookkeeping before each attempt to prevent the stale free.