Back to overview

CVE-2026-64136

CRITICAL
9.8
CVSS 3.1
Description
In the Linux kernel, the following vulnerability has been resolved: smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() Commit 96c4af418586 ("cifs: Fix locking usage for tcon fields") refactored cifs code to change cifs_tcp_ses_lock for tc_lock around tc_count changes. There was missing lock around tc_count increment inside smb2_find_smb_sess_tcon_unlocked().

Metadata

CVE ID
CVE-2026-64136
State
PUBLISHED
Assigner
Linux
Reserved
2026-07-19 07:54 UTC
Published
2026-07-19 15:40 UTC
Last updated
2026-07-20 13:43 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products (2)
VendorProductPlatformVersions
Linux Linux — 953953abb66e52c224057ab91e404284fefeab62 < 7df1df6f40c0720d30206aa35c0343b962350e0d, 601dd3b79769b38d30b693c40afdb2a4b7edf9d0 < 13fb413ae22a37c69341918a6d651d19a9b0b9b7, 3969db6b22e3d90d8c5f22ac1a7fe0350a94c136 < bf4ebdb19ff9b3cdf992b50715fe61633327416a, 96c4af418586ee9a6aab61738644366426e05316 < e374f4e496fef8168784f93a4477d67be34485fd …
Linux Linux — 7.0, 0 < 7.0, 6.6.142 ≤ 6.6.*, 6.12.92 ≤ 6.12.* …
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview