Linux Kernel Vulnerability in SMB2_close Functionality
CVE-2026-64597
What is CVE-2026-64597?
A vulnerability in the Linux kernel's SMB2_close functionality has been detected, where improper management of response buffers could lead to a double-free scenario. This occurs when a response-bearing attempt mistakenly frees the buffer before the next operation, potentially exposing the system to memory corruption risks. To rectify this issue, the kernel's handling of response bookkeeping has been refined, ensuring that the buffer is properly reset before each SMB2 close attempt, thus mitigating the risk of inadvertent memory access and maintaining system integrity.
Affected Version(s)
Linux 433042a91f9373241307725b52de573933ffedbf < 037511726228aaf165c7067ff2bfc88eaecdf1f3
Linux 4f1fffa2376922f3d1d506e49c0fd445b023a28e < 0aa97edf7c347c0f54e7e60c4740574b8120c66a
Linux 4f1fffa2376922f3d1d506e49c0fd445b023a28e