Back to overview

CVE-2026-64384

Description
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix change notify replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_notify_init() fails before the next send, cleanup retains the previous buffer type and frees that response again. Reset response bookkeeping before each attempt to prevent the stale free.

Metadata

CVE ID
CVE-2026-64384
State
PUBLISHED
Assigner
Linux
Reserved
2026-07-19 15:36 UTC
Published
2026-07-25 08:50 UTC
Last updated
2026-07-25 08:50 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux 433042a91f9373241307725b52de573933ffedbf < 5821f9dbb8b5b24391850a13418e633edd0fb003, 4f1fffa2376922f3d1d506e49c0fd445b023a28e < d684f4134998085702009b94c35c2003fc9e72d3, 4f1fffa2376922f3d1d506e49c0fd445b023a28e < 52af1975f0dfae990c5a0e85872cc41be0e88a68, 4f1fffa2376922f3d1d506e49c0fd445b023a28e < 901891513951bc8322ece754863909ea45af95c6 …
Linux Linux 6.8, 0 < 6.8, 6.6.145 ≤ 6.6.*, 6.12.96 ≤ 6.12.* …
Back to overview