Executive brief
A vulnerability was identified in the Linux kernel's SMB client, which is used to connect to network file shares. Under specific error conditions during a file 'open' request, the system could attempt to free the same memory buffer twice. This could lead to a system crash or instability, potentially disrupting access to network storage.
Technical details
A double-free vulnerability exists in the Linux kernel SMB client (cifs.ko) within the SMB2_open() function. When a replayable error occurs, the response buffer may be freed; however, if a subsequent call to SMB2_open_init() fails before the next network transmission, the cleanup routine may attempt to free the same buffer again because the response bookkeeping was not reset. This issue is triggered during SMB2 command retries. The fix involves resetting the response buffer type and zeroing the response I/O vector at the start of each replay attempt. Patches have been merged into multiple stable kernel branches.
Affected products
- Linux Linux Kernel 6.8 to 6.12.96, 6.18.39, 7.1.4
Timeline
- 2026-07-25: disclosed
- 2026-07-25: advisory
References
- https://git.kernel.org/stable/c/02bc2896bdc3e29362d6e40d404006944a159c25
- https://git.kernel.org/stable/c/14498ff5ce0f272ce0ef988721413e06b7038972
- https://git.kernel.org/stable/c/3196b5192f246df4272072f61a2f4a3e9967f55d
- https://git.kernel.org/stable/c/b55e182f2324bc6a604c21a47aa6c448f719a532
- https://git.kernel.org/stable/c/ff2d30927bc3bf3c629f0768d2068096e64ef5ce