CVE-2026-64384·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix change notify replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_notify_init() fails before the next send, cleanup retains the previous buffer type and frees that response again. Reset response bookkeeping before each attempt to prevent the stale free.
- Severity
- critical
- Software
- Kernel
- Fixed in
- 7.1.4
- Published
- 2026-07-25
Affected versions
From: 6.19
Until: 7.1.4
Fixed in: 7.1.4
How to fix this CVE
Update your Linux kernel to version 7.1.4 or later to resolve a critical double-free vulnerability in the SMB client change notify handler. This flaw occurs when replay logic fails to properly reset response buffer state between retry attempts, potentially leading to kernel memory corruption. Patch your systems immediately as this affects all kernel versions from 6.19 through 7.1.3.
sudo dnf update kernel kernel-develDefensia detects this vulnerability
How to check if you are affected
- Run `uname -r` to check your current kernel version; versions 6.19 to 7.1.3 are vulnerable
- Check if SMB client functionality is enabled with `cat /boot/config-$(uname -r) | grep CONFIG_SMB_CLIENT` (should show =y or =m if enabled)
- Search system logs for SMB change notification errors with `journalctl -u kernel -g 'smb.*notify' --no-pager | head -20` or `grep -i 'smb.*notify' /var/log/kern.log`
- Verify the patch by checking the kernel build date with `uname -v` and comparing against the release date of kernel 7.1.4 or later; confirm with `dpkg -l | grep linux-image` (Debian/Ubuntu) or `rpm -q kernel` (RHEL/CentOS)
FAQ
What is CVE-2026-64384?
This is a critical double-free vulnerability in the Linux kernel's SMB client implementation, specifically in the change notify replay mechanism. When a replayable error occurs during SMB2 change notification, the kernel fails to properly reset internal buffer state before the next retry attempt, causing the same memory to be freed twice and potentially leading to arbitrary kernel code execution.
Is CVE-2026-64384 being actively exploited?
No, this vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities catalog, and no public exploits are available. However, the critical CVSS score of 9.8 means systems should still be patched immediately as exploitation is theoretically possible.
What versions of Kernel are affected by CVE-2026-64384?
Linux kernel versions 6.19 through 7.1.3 are vulnerable. Kernel 7.1.4 and all later versions contain the fix.
How do I check if my server is vulnerable to CVE-2026-64384?
Run `uname -r` and note the kernel version. If it falls between 6.19 and 7.1.3 (inclusive), your system is vulnerable. You can also run `apt list --upgradable 2>/dev/null | grep linux-image` (Ubuntu/Debian) or `dnf check-update kernel` (RHEL/CentOS) to see if kernel updates are available.
Does Defensia detect CVE-2026-64384?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2026-64384 will appear in your dashboard with remediation steps and version guidance.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/145f820dcbb2cced374f2532f8a61a44dce4a615
- https://git.kernel.org/stable/c/52af1975f0dfae990c5a0e85872cc41be0e88a68
- https://git.kernel.org/stable/c/5821f9dbb8b5b24391850a13418e633edd0fb003
- https://git.kernel.org/stable/c/901891513951bc8322ece754863909ea45af95c6
- https://git.kernel.org/stable/c/d684f4134998085702009b94c35c2003fc9e72d3
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-64384. Free for 1 server.
Get started free