CVE-2026-45972 PUBLISHED

smb: client: fix potential UAF and double free in smb2_open_file()

Assigner: Linux
Reserved: 13.05.2026 Published: 27.05.2026 Updated: 27.05.2026

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix potential UAF and double free in smb2_open_file()

Zero out @err_iov and @err_buftype before retrying SMB2_open() to prevent an UAF bug if @data != NULL, otherwise a double free.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 743f70406264348c0830f38409eb6c40a42fb2db to 96e53bb3ee2f354cf6b4ab07bcc56e500f8b3f74 (excl.)
  • affected from 3a6d6b332f92990958602c1e35ce0173e2dd62e9 to 7425453ea16dbc3bbb0f6cac4d60b537e5e4d151 (excl.)
  • affected from b64e3b5d8d759dd4333992e4ba4dadf9359952c8 to 4d339b219004869e96c4ce56b8891f83a38da4c0 (excl.)
  • affected from 9ee608a64e37cea5b4b13e436c559dd0fb2ad1b5 to e66dcf7bb9c4df5582c82bc3582725abcbfbea73 (excl.)
  • affected from e3a43633023e3cacaca60d4b8972d084a2b06236 to 639deb962986ef2f5e2a6d5a600c66f922471e81 (excl.)
  • affected from e3a43633023e3cacaca60d4b8972d084a2b06236 to ebbbc4bfad4cb355d17c671223d0814ee3ef4eda (excl.)
  • affected from 6.1.163 to 6.1.165 (excl.)
  • affected from 6.6.124 to 6.6.128 (excl.)
  • affected from 6.12.70 to 6.12.75 (excl.)
  • affected from 6.18.10 to 6.18.14 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.19 is affected
  • unaffected from 0 to 6.19 (excl.)
  • unaffected from 6.1.165 to 6.1.* (incl.)
  • unaffected from 6.6.128 to 6.6.* (incl.)
  • unaffected from 6.12.75 to 6.12.* (incl.)
  • unaffected from 6.18.14 to 6.18.* (incl.)
  • unaffected from 6.19.4 to 6.19.* (incl.)
  • unaffected from 7.0 to * (incl.)

References