SB20260727191 - Double free in Linux kernel smb client
Published: July 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Double free (CVE-ID: CVE-2026-64384)
CWE-ID: CWE-415 - Double Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to double free in SMB change notify handling in fs/smb/client/smb2pdu.c when processing replayable error conditions during change notify requests. A local user can trigger a replayable error and subsequent cleanup to free the same response buffer twice to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/145f820dcbb2cced374f2532f8a61a44dce4a615
- https://git.kernel.org/stable/c/52af1975f0dfae990c5a0e85872cc41be0e88a68
- https://git.kernel.org/stable/c/5821f9dbb8b5b24391850a13418e633edd0fb003
- https://git.kernel.org/stable/c/901891513951bc8322ece754863909ea45af95c6
- https://git.kernel.org/stable/c/d684f4134998085702009b94c35c2003fc9e72d3