CVE-2026-64597 is a vulnerability in Linux Kernel
Published on August 6, 2026
smb: client: fix double-free in SMB2_close() replay
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix double-free in SMB2_close() replay
A response-bearing attempt can return a replayable error and free its
response buffer. If SMB2_close_init() fails before the next send, cleanup
retains the previous buffer type and frees that response again.
Reset response bookkeeping before each attempt to prevent the stale free.
Products Associated with CVE-2026-64597
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 433042a91f9373241307725b52de573933ffedbf and below 037511726228aaf165c7067ff2bfc88eaecdf1f3 is affected.
- Version 4f1fffa2376922f3d1d506e49c0fd445b023a28e and below 0aa97edf7c347c0f54e7e60c4740574b8120c66a is affected.
- Version 4f1fffa2376922f3d1d506e49c0fd445b023a28e and below d15d83125007f673aec4323e1bbbaaffbe87ea13 is affected.
- Version 4f1fffa2376922f3d1d506e49c0fd445b023a28e and below b18ed621dbfceecea5539848cddcb9272c9a61e1 is affected.
- Version 4f1fffa2376922f3d1d506e49c0fd445b023a28e and below f96e1cdcb63ed3321142ff2fcdf784e32cda8fee is affected.
- Version 6.6.32 and below 6.6.145 is affected.
- Version 6.8 is affected.
- Before 6.8 is unaffected.
- Version 6.6.145, <= 6.6.* is unaffected.
- Version 6.12.96, <= 6.12.* is unaffected.
- Version 6.18.39, <= 6.18.* is unaffected.
- Version 7.1.4, <= 7.1.* is unaffected.
- Version 7.2-rc1, <= * is unaffected.