AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-64597

CRITICAL · CVSS 9.8 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's SMB2 client implementation, specifically in the SMB2_close() function, where a double-free condition can occur due to improper handling of response buffers during error scenarios. This flaw could potentially lead to memory corruption or denial of service, impacting system stability and security. Organizations utilizing Linux systems with SMB2 functionality should prioritize patching to mitigate potential exploitation risks.

CVE
CVE-2026-64597
Severity
CRITICAL
CVSS
9.8
EPSS
0.36%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_close_init() fails before the next send, cleanup retains the previous buffer type and frees that response again. Reset response bookkeeping before each attempt to prevent the stale free.