SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-64387

CRITICAL · CVSS 9.8 EPSS 0.46%

Source: NVD + CISA KEV + EPSS · Published 2026-07-25 · Last synced 2026-08-24

CyberRota Analysis

AI-Generated

A critical vulnerability in the Linux kernel affects the SMB client, where a double-free condition can occur during directory query operations due to improper handling of response buffers. This flaw could lead to potential denial-of-service attacks or arbitrary code execution, making it essential for organizations using Linux systems, particularly those relying on SMB for file sharing, to prioritize patching. Immediate action is recommended for system administrators and security teams to mitigate risks associated with this vulnerability.

CVE
CVE-2026-64387
Severity
CRITICAL
CVSS
9.8
EPSS
0.46%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix query directory replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_query_directory_init() fails before the next send, cleanup retains the previous buffer type and frees that response again. Reset response bookkeeping before each attempt to prevent the stale free.