Junglewise Threat Intelligence

CVE-2026-64386: Linux Kernel SMB client double-free in query_info

CVE-2026-64386 · Severity: info · CVSS 0 · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's SMB client, which is used to connect to Windows-style file shares. Under specific network error conditions, the system could attempt to free the same memory buffer twice, potentially leading to a system crash or instability. This affects the reliability of file sharing services on Linux-based systems.

Technical details

A double-free vulnerability exists in the Linux kernel SMB client (cifs.ko) within the query_info() function. When a response-bearing attempt returns a replayable error, the response buffer is freed. If a subsequent call to SMB2_query_info_init() fails before the next network send, the cleanup routine incorrectly retains the previous buffer type and attempts to free the already-freed buffer. The fix involves resetting the response bookkeeping (resp_buftype and rsp_iov) before each replay attempt to prevent stale memory references. This issue was introduced by the replay flag logic in the SMB2 PDU handling code.

Affected products

  • Linux Linux Kernel 6.6.32 to 6.6.145, 6.8 to 7.2-rc1

Timeline

  • 2026-06-18: patched: Initial fix committed to kernel source
  • 2026-07-25: disclosed: CVE published

References

Related threats