SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-64384

CRITICAL · CVSS 9.8 EPSS 0.46%

Source: NVD + CISA KEV + EPSS · Published 2026-07-25 · Last synced 2026-08-24

CyberRota Analysis

AI-Generated

A critical vulnerability in the Linux kernel affects the SMB client, where a double-free condition can occur due to improper handling of response buffers during change notifications. This flaw can lead to potential memory corruption, allowing attackers to exploit the system for arbitrary code execution or denial of service. Organizations using Linux systems, particularly those relying on SMB for file sharing, should prioritize patching to mitigate the risk associated with this vulnerability.

CVE
CVE-2026-64384
Severity
CRITICAL
CVSS
9.8
EPSS
0.46%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix change notify replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_notify_init() fails before the next send, cleanup retains the previous buffer type and frees that response again. Reset response bookkeeping before each attempt to prevent the stale free.