Double free in Linux kernel - CVE-2026-64384
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to double free in SMB change notify handling in fs/smb/client/smb2pdu.c when processing replayable error conditions during change notify requests. A local user can trigger a replayable error and subsequent cleanup to free the same response buffer twice to cause a denial of service.
Affected software
How to mitigate CVE-2026-64384
External References
- https://git.kernel.org/stable/c/145f820dcbb2cced374f2532f8a61a44dce4a615
- https://git.kernel.org/stable/c/52af1975f0dfae990c5a0e85872cc41be0e88a68
- https://git.kernel.org/stable/c/5821f9dbb8b5b24391850a13418e633edd0fb003
- https://git.kernel.org/stable/c/901891513951bc8322ece754863909ea45af95c6
- https://git.kernel.org/stable/c/d684f4134998085702009b94c35c2003fc9e72d3