CVE-2026-64597 PUBLISHED

smb: client: fix double-free in SMB2_close() replay

Assigner: Linux
Reserved: 19.07.2026 Published: 06.08.2026 Updated: 06.08.2026

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix double-free in SMB2_close() replay

A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_close_init() fails before the next send, cleanup retains the previous buffer type and frees that response again.

Reset response bookkeeping before each attempt to prevent the stale free.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 433042a91f9373241307725b52de573933ffedbf to 037511726228aaf165c7067ff2bfc88eaecdf1f3 (excl.)
  • affected from 4f1fffa2376922f3d1d506e49c0fd445b023a28e to 0aa97edf7c347c0f54e7e60c4740574b8120c66a (excl.)
  • affected from 4f1fffa2376922f3d1d506e49c0fd445b023a28e to d15d83125007f673aec4323e1bbbaaffbe87ea13 (excl.)
  • affected from 4f1fffa2376922f3d1d506e49c0fd445b023a28e to b18ed621dbfceecea5539848cddcb9272c9a61e1 (excl.)
  • affected from 4f1fffa2376922f3d1d506e49c0fd445b023a28e to f96e1cdcb63ed3321142ff2fcdf784e32cda8fee (excl.)
  • affected from 6.6.32 to 6.6.145 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.8 is affected
  • unaffected from 0 to 6.8 (excl.)
  • unaffected from 6.6.145 to 6.6.* (incl.)
  • unaffected from 6.12.96 to 6.12.* (incl.)
  • unaffected from 6.18.39 to 6.18.* (incl.)
  • unaffected from 7.1.4 to 7.1.* (incl.)
  • unaffected from 7.2-rc1 to * (incl.)

References