Double free in Linux kernel - CVE-2026-64387
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a double free in SMB2_query_directory in the SMB client when handling replayed query directory responses and reinitialization failures. A local user can trigger a replayable error and subsequent cleanup conditions to cause a denial of service.
Affected software
How to mitigate CVE-2026-64387
External References
- https://git.kernel.org/stable/c/00b0fa425941438b664950a8ee65dfba2def4336
- https://git.kernel.org/stable/c/1665f25b1dea30bf2d02e16245d203a944c9d994
- https://git.kernel.org/stable/c/3317a5d015fca976475aa71df224056777316fde
- https://git.kernel.org/stable/c/3409aedf3c81a810243da94164f6621c9d205c98
- https://git.kernel.org/stable/c/9647492b5e41954be59d5157eddbcd4cdc1656f7