critical CVSS 9.8

CVE-2026-64384·Kernel vulnerability

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix change notify replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_notify_init() fails before the next send, cleanup retains the previous buffer type and frees that response again. Reset response bookkeeping before each attempt to prevent the stale free.

Severity
critical
Software
Kernel
Fixed in
7.1.4
Published
2026-07-25

Affected versions

From: 6.19

Until: 7.1.4

Fixed in: 7.1.4

How to fix this CVE

Update your Linux kernel to version 7.1.4 or later to resolve a critical double-free vulnerability in the SMB client change notify handler. This flaw occurs when replay logic fails to properly reset response buffer state between retry attempts, potentially leading to kernel memory corruption. Patch your systems immediately as this affects all kernel versions from 6.19 through 7.1.3.

sudo dnf update kernel kernel-devel

Defensia detects this vulnerability

How to check if you are affected

  1. Run `uname -r` to check your current kernel version; versions 6.19 to 7.1.3 are vulnerable
  2. Check if SMB client functionality is enabled with `cat /boot/config-$(uname -r) | grep CONFIG_SMB_CLIENT` (should show =y or =m if enabled)
  3. Search system logs for SMB change notification errors with `journalctl -u kernel -g 'smb.*notify' --no-pager | head -20` or `grep -i 'smb.*notify' /var/log/kern.log`
  4. Verify the patch by checking the kernel build date with `uname -v` and comparing against the release date of kernel 7.1.4 or later; confirm with `dpkg -l | grep linux-image` (Debian/Ubuntu) or `rpm -q kernel` (RHEL/CentOS)

FAQ

What is CVE-2026-64384?

This is a critical double-free vulnerability in the Linux kernel's SMB client implementation, specifically in the change notify replay mechanism. When a replayable error occurs during SMB2 change notification, the kernel fails to properly reset internal buffer state before the next retry attempt, causing the same memory to be freed twice and potentially leading to arbitrary kernel code execution.

Is CVE-2026-64384 being actively exploited?

No, this vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities catalog, and no public exploits are available. However, the critical CVSS score of 9.8 means systems should still be patched immediately as exploitation is theoretically possible.

What versions of Kernel are affected by CVE-2026-64384?

Linux kernel versions 6.19 through 7.1.3 are vulnerable. Kernel 7.1.4 and all later versions contain the fix.

How do I check if my server is vulnerable to CVE-2026-64384?

Run `uname -r` and note the kernel version. If it falls between 6.19 and 7.1.3 (inclusive), your system is vulnerable. You can also run `apt list --upgradable 2>/dev/null | grep linux-image` (Ubuntu/Debian) or `dnf check-update kernel` (RHEL/CentOS) to see if kernel updates are available.

Does Defensia detect CVE-2026-64384?

Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2026-64384 will appear in your dashboard with remediation steps and version guidance.

Related Kernel CVEs

CVE-2026-64056CVSS 9.8In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Make RX SKB per-port The SKB used to assemble packets from fragments in gmac_rx() is static local, but the Gemini has two ethernet ports, meaning there can be races between the ports on a bad day if a device is using both. Make the RX SKB a per-port variable and carry it over between invocations in the port struct instead. Zero the pointer once we call napi_gro_frags(), on error (after calling napi_free_frags()) or if the port is stopped. Zero it in some place where not strictly necessary just to emphasize what is going on. This was found by Sashiko during normal patch review.
CVE-2026-64383CVSS 9.8In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_flush() replay SMB2_flush() keeps its response buffer bookkeeping across replay attempts. If a replayable flush response is received and the retry then fails before cifs_send_recv() stores a replacement response, flush_exit will free the stale response pointer a second time. Reinitialize resp_buftype and rsp_iov at the top of the replay loop so cleanup only acts on response state produced by the current attempt. This fixes a double-free without changing replay handling for successful requests.
CVE-2026-64055CVSS 9.8In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Carry over frag counter The gmac_rx() NAPI poll function assembles packets in an SKB from a ring buffer. If the ring buffer gets completely emptied during a poll cycle, we exit gmac_rx(), but the packet is not yet completely assembled in the SKB, yet the fragment counter frag_nr is reset to zero on the next invocation. Solve this by making the RX fragment counter a part of the port struct, and carry it over between invocations. Reset the fragment counter only right after calling napi_gro_frags(), on error (after calling napi_free_frags()) or if stopping the port. Reset it in some place where not strictly necessary just to emphasize what is going on. This was found by Sashiko during normal patch review.
CVE-2026-64385CVSS 9.8In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_ioctl() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_ioctl_init() fails before the next send, cleanup retains the previous buffer type and frees that response again. Reset response bookkeeping before each attempt to prevent the stale free.
CVE-2026-64061CVSS 9.8In the Linux kernel, the following vulnerability has been resolved: netfs: Fix early put of sink folio in netfs_read_gaps() Fix netfs_read_gaps() to release the sink page it uses after waiting for the request to complete. The way the sink page is used is that an ITER_BVEC-class iterator is created that has the gaps from the target folio at either end, but has the sink page tiled over the middle so that a single read op can fill in both gaps. The bug was found by KASAN detecting a UAF on the generic/075 xfstest in the cifsd kernel thread that handles reception of data from the TCP socket: BUG: KASAN: use-after-free in _copy_to_iter+0x48a/0xa20 Write of size 885 at addr ffff888107f92000 by task cifsd/1285 CPU: 2 UID: 0 PID: 1285 Comm: cifsd Not tainted 7.0.0 #6 PREEMPT(lazy) Call Trace: dump_stack_lvl+0x5d/0x80 print_report+0x17f/0x4f1 kasan_report+0x100/0x1e0 kasan_check_range+0x10f/0x1e0 __asan_memcpy+0x3c/0x60 _copy_to_iter+0x48a/0xa20 __skb_datagram_iter+0x2c9/0x430 skb_copy_datagram_iter+0x6e/0x160 tcp_recvmsg_locked+0xce0/0x1130 tcp_recvmsg+0xeb/0x300 inet_recvmsg+0xcf/0x3a0 sock_recvmsg+0xea/0x100 cifs_readv_from_socket+0x3a6/0x4d0 [cifs] cifs_read_iter_from_socket+0xdd/0x130 [cifs] cifs_readv_receive+0xaad/0xb10 [cifs] cifs_demultiplex_thread+0x1148/0x1740 [cifs] kthread+0x1cf/0x210

References

Track CVEs across your fleet automatically

Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-64384. Free for 1 server.

Get started free