CVE-2026-64383·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_flush() replay SMB2_flush() keeps its response buffer bookkeeping across replay attempts. If a replayable flush response is received and the retry then fails before cifs_send_recv() stores a replacement response, flush_exit will free the stale response pointer a second time. Reinitialize resp_buftype and rsp_iov at the top of the replay loop so cleanup only acts on response state produced by the current attempt. This fixes a double-free without changing replay handling for successful requests.
- Severity
- critical
- Software
- Kernel
- Fixed in
- 7.1.4
- Published
- 2026-07-25
Affected versions
From: 6.19
Until: 7.1.4
Fixed in: 7.1.4
How to fix this CVE
Update your Linux kernel to version 7.1.4 or later to resolve a critical double-free memory corruption vulnerability in the SMB2 client flush operation. This flaw affects kernel versions 6.19 through 7.1.3 and can lead to kernel crashes or potential code execution during SMB protocol replay scenarios. Apply the patch immediately on all affected systems, particularly those using SMB/CIFS file sharing.
sudo dnf update kernel kernel-develDefensia detects this vulnerability
How to check if you are affected
- Step 1: Check your current kernel version with `uname -r` and compare against the vulnerable range (6.19 to 7.1.3)
- Step 2: Verify SMB/CIFS client is enabled by checking `lsmod | grep cifs` or `grep -i cifs /proc/modules`
- Step 3: Review kernel logs for SMB flush errors or double-free warnings with `dmesg | grep -i 'double.*free\|smb.*flush\|cifs'` or check `/var/log/kern.log`
- Step 4: After patching, confirm the new kernel is loaded with `uname -r` and reboot if necessary with `sudo reboot`
FAQ
What is CVE-2026-64383?
CVE-2026-64383 is a critical double-free vulnerability in the Linux kernel's SMB2 client implementation that occurs when handling flush operations during protocol replay. If a flush response is received and a subsequent retry fails before the response buffer is properly replaced, the cleanup routine will attempt to free the same memory region twice, potentially causing a kernel panic or denial of service.
Is CVE-2026-64383 being actively exploited?
No, this vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog and no public exploits are available. However, the critical CVSS 9.8 score indicates high severity and patches should be deployed promptly.
What versions of Kernel are affected by CVE-2026-64383?
Linux kernel versions 6.19 through 7.1.3 are vulnerable. Version 7.1.4 and later contain the fix.
How do I check if my server is vulnerable to CVE-2026-64383?
Run `uname -r` to obtain your kernel version and verify it falls within the 6.19 to 7.1.3 range. Additionally, confirm SMB/CIFS functionality is in use with `lsmod | grep cifs`. If both conditions are true, your system is vulnerable.
Does Defensia detect CVE-2026-64383?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2026-64383 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/013a9a3da46c5dabcf18f65ea6a47874ba12a15d
- https://git.kernel.org/stable/c/3407240cde132a4b72d6429a2625a09a2f78adaf
- https://git.kernel.org/stable/c/4be31c943a3a27a5a0251dbb8f5cb89059ec3d5a
- https://git.kernel.org/stable/c/6e27f40b682a5e42a2daae3ce6d96f0e0e16dedb
- https://git.kernel.org/stable/c/878757163eea684750107a31ea134c103863515d
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-64383. Free for 1 server.
Get started free