critical CVSS 9.8

CVE-2026-64383·Kernel vulnerability

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_flush() replay SMB2_flush() keeps its response buffer bookkeeping across replay attempts. If a replayable flush response is received and the retry then fails before cifs_send_recv() stores a replacement response, flush_exit will free the stale response pointer a second time. Reinitialize resp_buftype and rsp_iov at the top of the replay loop so cleanup only acts on response state produced by the current attempt. This fixes a double-free without changing replay handling for successful requests.

Severity
critical
Software
Kernel
Fixed in
7.1.4
Published
2026-07-25

Affected versions

From: 6.19

Until: 7.1.4

Fixed in: 7.1.4

How to fix this CVE

Update your Linux kernel to version 7.1.4 or later to resolve a critical double-free memory corruption vulnerability in the SMB2 client flush operation. This flaw affects kernel versions 6.19 through 7.1.3 and can lead to kernel crashes or potential code execution during SMB protocol replay scenarios. Apply the patch immediately on all affected systems, particularly those using SMB/CIFS file sharing.

sudo dnf update kernel kernel-devel

Defensia detects this vulnerability

How to check if you are affected

  1. Step 1: Check your current kernel version with `uname -r` and compare against the vulnerable range (6.19 to 7.1.3)
  2. Step 2: Verify SMB/CIFS client is enabled by checking `lsmod | grep cifs` or `grep -i cifs /proc/modules`
  3. Step 3: Review kernel logs for SMB flush errors or double-free warnings with `dmesg | grep -i 'double.*free\|smb.*flush\|cifs'` or check `/var/log/kern.log`
  4. Step 4: After patching, confirm the new kernel is loaded with `uname -r` and reboot if necessary with `sudo reboot`

FAQ

What is CVE-2026-64383?

CVE-2026-64383 is a critical double-free vulnerability in the Linux kernel's SMB2 client implementation that occurs when handling flush operations during protocol replay. If a flush response is received and a subsequent retry fails before the response buffer is properly replaced, the cleanup routine will attempt to free the same memory region twice, potentially causing a kernel panic or denial of service.

Is CVE-2026-64383 being actively exploited?

No, this vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog and no public exploits are available. However, the critical CVSS 9.8 score indicates high severity and patches should be deployed promptly.

What versions of Kernel are affected by CVE-2026-64383?

Linux kernel versions 6.19 through 7.1.3 are vulnerable. Version 7.1.4 and later contain the fix.

How do I check if my server is vulnerable to CVE-2026-64383?

Run `uname -r` to obtain your kernel version and verify it falls within the 6.19 to 7.1.3 range. Additionally, confirm SMB/CIFS functionality is in use with `lsmod | grep cifs`. If both conditions are true, your system is vulnerable.

Does Defensia detect CVE-2026-64383?

Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2026-64383 will appear in your dashboard with remediation steps.

Related Kernel CVEs

CVE-2026-64056CVSS 9.8In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Make RX SKB per-port The SKB used to assemble packets from fragments in gmac_rx() is static local, but the Gemini has two ethernet ports, meaning there can be races between the ports on a bad day if a device is using both. Make the RX SKB a per-port variable and carry it over between invocations in the port struct instead. Zero the pointer once we call napi_gro_frags(), on error (after calling napi_free_frags()) or if the port is stopped. Zero it in some place where not strictly necessary just to emphasize what is going on. This was found by Sashiko during normal patch review.
CVE-2026-64384CVSS 9.8In the Linux kernel, the following vulnerability has been resolved: smb: client: fix change notify replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_notify_init() fails before the next send, cleanup retains the previous buffer type and frees that response again. Reset response bookkeeping before each attempt to prevent the stale free.
CVE-2026-64055CVSS 9.8In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Carry over frag counter The gmac_rx() NAPI poll function assembles packets in an SKB from a ring buffer. If the ring buffer gets completely emptied during a poll cycle, we exit gmac_rx(), but the packet is not yet completely assembled in the SKB, yet the fragment counter frag_nr is reset to zero on the next invocation. Solve this by making the RX fragment counter a part of the port struct, and carry it over between invocations. Reset the fragment counter only right after calling napi_gro_frags(), on error (after calling napi_free_frags()) or if stopping the port. Reset it in some place where not strictly necessary just to emphasize what is going on. This was found by Sashiko during normal patch review.
CVE-2026-64385CVSS 9.8In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_ioctl() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_ioctl_init() fails before the next send, cleanup retains the previous buffer type and frees that response again. Reset response bookkeeping before each attempt to prevent the stale free.
CVE-2026-64061CVSS 9.8In the Linux kernel, the following vulnerability has been resolved: netfs: Fix early put of sink folio in netfs_read_gaps() Fix netfs_read_gaps() to release the sink page it uses after waiting for the request to complete. The way the sink page is used is that an ITER_BVEC-class iterator is created that has the gaps from the target folio at either end, but has the sink page tiled over the middle so that a single read op can fill in both gaps. The bug was found by KASAN detecting a UAF on the generic/075 xfstest in the cifsd kernel thread that handles reception of data from the TCP socket: BUG: KASAN: use-after-free in _copy_to_iter+0x48a/0xa20 Write of size 885 at addr ffff888107f92000 by task cifsd/1285 CPU: 2 UID: 0 PID: 1285 Comm: cifsd Not tainted 7.0.0 #6 PREEMPT(lazy) Call Trace: dump_stack_lvl+0x5d/0x80 print_report+0x17f/0x4f1 kasan_report+0x100/0x1e0 kasan_check_range+0x10f/0x1e0 __asan_memcpy+0x3c/0x60 _copy_to_iter+0x48a/0xa20 __skb_datagram_iter+0x2c9/0x430 skb_copy_datagram_iter+0x6e/0x160 tcp_recvmsg_locked+0xce0/0x1130 tcp_recvmsg+0xeb/0x300 inet_recvmsg+0xcf/0x3a0 sock_recvmsg+0xea/0x100 cifs_readv_from_socket+0x3a6/0x4d0 [cifs] cifs_read_iter_from_socket+0xdd/0x130 [cifs] cifs_readv_receive+0xaad/0xb10 [cifs] cifs_demultiplex_thread+0x1148/0x1740 [cifs] kthread+0x1cf/0x210

References

Track CVEs across your fleet automatically

Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-64383. Free for 1 server.

Get started free