CVE-2026-64385·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_ioctl() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_ioctl_init() fails before the next send, cleanup retains the previous buffer type and frees that response again. Reset response bookkeeping before each attempt to prevent the stale free.
- Severity
- critical
- Software
- Kernel
- Fixed in
- 7.1.4
- Published
- 2026-07-25
Affected versions
From: 6.19
Until: 7.1.4
Fixed in: 7.1.4
How to fix this CVE
Update your Linux kernel to version 7.1.4 or later to patch a critical double-free vulnerability in SMB2 ioctl operations that could allow local privilege escalation or denial of service. The vulnerability occurs when SMB2_ioctl() replay logic fails to properly reset response buffer bookkeeping, causing a previously-freed buffer to be freed again during error handling. Prioritize this update as it affects kernel versions 6.19 through 7.1.3 with a CVSS score of 9.8.
sudo dnf update kernel kernel-headers kernel-develDefensia detects this vulnerability
How to check if you are affected
- Step 1: Check your current kernel version with `uname -r` and compare against the affected range (6.19 to 7.1.3)
- Step 2: Verify SMB client functionality is enabled in your kernel config with `grep CONFIG_CIFS /boot/config-$(uname -r)` (should show CONFIG_CIFS=y or =m)
- Step 3: Search system logs for SMB2 ioctl errors using `journalctl -u kernel | grep -i 'smb2\|ioctl\|replay' | head -20`
- Step 4: After patching, confirm kernel version with `uname -r` shows 7.1.4 or later and reboot to activate changes
FAQ
What is CVE-2026-64385?
This is a double-free memory corruption vulnerability in the Linux kernel's SMB2 client implementation. When an SMB2 ioctl operation encounters a replayable error during retry logic, the response buffer cleanup fails to reset its bookkeeping state, leading to the same buffer being freed twice and potentially allowing code execution with kernel privileges.
Is CVE-2026-64385 being actively exploited?
No, this vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities (KEV) catalog and no public exploits are available. However, the CVSS 9.8 severity warrants immediate patching due to the critical nature of the flaw.
What versions of Kernel are affected by CVE-2026-64385?
Linux kernel versions 6.19 through 7.1.3 are vulnerable. Kernel 7.1.4 and later versions contain the fix.
How do I check if my server is vulnerable to CVE-2026-64385?
Run `uname -r` to get your kernel version. If it shows 6.19.x through 7.1.3, you are vulnerable. Cross-reference with `grep CONFIG_CIFS /boot/config-$(uname -r)` to confirm SMB2 client support is compiled in.
Does Defensia detect CVE-2026-64385?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2026-64385 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/0be4bc64882edaefaaee8d1e27d083643eb778e6
- https://git.kernel.org/stable/c/276c8efbc49f9303ac76d0d4deab7128581b0f3b
- https://git.kernel.org/stable/c/96fcfc8ae7359346156e492ca610e830d2649ad6
- https://git.kernel.org/stable/c/f9bbadb6c94583e3b4af1afc449bfceb1d1ddec9
- https://git.kernel.org/stable/c/fc65ffb4ef1bf540da16b17c225ae51091e07d72
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-64385. Free for 1 server.
Get started free