Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-64382

Опубликовано: 25 июл. 2026
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

A flaw was found in the Linux kernel's Server Message Block (SMB) client. A double-free vulnerability exists in the SMB2_open() replay mechanism. This occurs when a response-bearing attempt returns a replayable error and frees its response buffer, and then the cleanup process attempts to free the same buffer again. This memory corruption vulnerability could potentially lead to a denial of service or, in some cases, arbitrary code execution.

Дополнительная информация

Статус:

Important
Дефект:
CWE-1341
https://bugzilla.redhat.com/show_bug.cgi?id=2507042kernel: smb: client: fix double-free in SMB2_open() replay

EPSS

Процентиль: 28%
0.00354
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
7 дней назад

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_open() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_open_init() fails before the next send, cleanup retains the previous buffer type and frees that response again. Reset response bookkeeping before each attempt to prevent the stale free.

CVSS3: 8.8
nvd
7 дней назад

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_open() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_open_init() fails before the next send, cleanup retains the previous buffer type and frees that response again. Reset response bookkeeping before each attempt to prevent the stale free.

msrc
6 дней назад

smb: client: fix double-free in SMB2_open() replay

CVSS3: 8.8
debian
7 дней назад

In the Linux kernel, the following vulnerability has been resolved: s ...

CVSS3: 8.8
github
7 дней назад

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_open() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_open_init() fails before the next send, cleanup retains the previous buffer type and frees that response again. Reset response bookkeeping before each attempt to prevent the stale free.

EPSS

Процентиль: 28%
0.00354
Низкий

7 High

CVSS3