Use-after-free in Linux kernel - CVE-2026-64437
Published: July 27, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to use-after-free in smb2_cancel() and deferred byte-range lock handling in ksmbd when processing an SMB2_CLOSE followed by an SMB2_CANCEL for the same AsyncId. A remote user can send crafted SMB requests to cause a denial of service.
Exploitation requires authentication to the SMB service and access to a locking handle associated with deferred work.
How to mitigate CVE-2026-64437
Sources
- https://git.kernel.org/stable/c/10f293a07f9e10e988b0ae44e2e99c631f5a68e0
- https://git.kernel.org/stable/c/12c36c99655f325befe50c26842f7deca414c381
- https://git.kernel.org/stable/c/94083db751930b1540ddff2b54d4677549c57f81
- https://git.kernel.org/stable/c/a796ba4e61d5e14e07b79a359faac69f8f9b22a3
- https://git.kernel.org/stable/c/b8e274e69ab09222c7a552c7c0c1eef9ce627fc1
- https://git.kernel.org/stable/c/ddb9239828336b36d8a3ef5943fdffb2f55b6508