Executive brief
A vulnerability was identified in the Linux kernel's SMB client, which is used to connect to Windows-style file shares. Under specific network error conditions, the system could attempt to free the same memory buffer twice, potentially leading to a system crash or instability. This affects the reliability of file sharing services on Linux-based systems.
Technical details
A double-free vulnerability exists in the Linux kernel SMB client (cifs.ko) within the query_info() function. When a response-bearing attempt returns a replayable error, the response buffer is freed. If a subsequent call to SMB2_query_info_init() fails before the next network send, the cleanup routine incorrectly retains the previous buffer type and attempts to free the already-freed buffer. The fix involves resetting the response bookkeeping (resp_buftype and rsp_iov) before each replay attempt to prevent stale memory references. This issue was introduced by the replay flag logic in the SMB2 PDU handling code.
Affected products
- Linux Linux Kernel 6.6.32 to 6.6.145, 6.8 to 7.2-rc1
Timeline
- 2026-06-18: patched: Initial fix committed to kernel source
- 2026-07-25: disclosed: CVE published
References
- https://git.kernel.org/stable/c/100fb7c455fa86d248b8bd7bb9de757c192870b4
- https://git.kernel.org/stable/c/2a88561d66eb855813cf004a0abe648bbb17de5e
- https://git.kernel.org/stable/c/3c81dda84799f76b42aec598564316e2964440db
- https://git.kernel.org/stable/c/89234773e8348918111aa15f6922b58cf3843364
- https://git.kernel.org/stable/c/f1add4acb656f5a82806a1ab0e63fed3d8b1bfca