critical CVSS 9.8

CVE-2026-64385·Kernel vulnerability

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_ioctl() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_ioctl_init() fails before the next send, cleanup retains the previous buffer type and frees that response again. Reset response bookkeeping before each attempt to prevent the stale free.

Severity
critical
Software
Kernel
Fixed in
7.1.4
Published
2026-07-25

Affected versions

From: 6.19

Until: 7.1.4

Fixed in: 7.1.4

How to fix this CVE

Update your Linux kernel to version 7.1.4 or later to patch a critical double-free vulnerability in SMB2 ioctl operations that could allow local privilege escalation or denial of service. The vulnerability occurs when SMB2_ioctl() replay logic fails to properly reset response buffer bookkeeping, causing a previously-freed buffer to be freed again during error handling. Prioritize this update as it affects kernel versions 6.19 through 7.1.3 with a CVSS score of 9.8.

sudo dnf update kernel kernel-headers kernel-devel

Defensia detects this vulnerability

How to check if you are affected

  1. Step 1: Check your current kernel version with `uname -r` and compare against the affected range (6.19 to 7.1.3)
  2. Step 2: Verify SMB client functionality is enabled in your kernel config with `grep CONFIG_CIFS /boot/config-$(uname -r)` (should show CONFIG_CIFS=y or =m)
  3. Step 3: Search system logs for SMB2 ioctl errors using `journalctl -u kernel | grep -i 'smb2\|ioctl\|replay' | head -20`
  4. Step 4: After patching, confirm kernel version with `uname -r` shows 7.1.4 or later and reboot to activate changes

FAQ

What is CVE-2026-64385?

This is a double-free memory corruption vulnerability in the Linux kernel's SMB2 client implementation. When an SMB2 ioctl operation encounters a replayable error during retry logic, the response buffer cleanup fails to reset its bookkeeping state, leading to the same buffer being freed twice and potentially allowing code execution with kernel privileges.

Is CVE-2026-64385 being actively exploited?

No, this vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities (KEV) catalog and no public exploits are available. However, the CVSS 9.8 severity warrants immediate patching due to the critical nature of the flaw.

What versions of Kernel are affected by CVE-2026-64385?

Linux kernel versions 6.19 through 7.1.3 are vulnerable. Kernel 7.1.4 and later versions contain the fix.

How do I check if my server is vulnerable to CVE-2026-64385?

Run `uname -r` to get your kernel version. If it shows 6.19.x through 7.1.3, you are vulnerable. Cross-reference with `grep CONFIG_CIFS /boot/config-$(uname -r)` to confirm SMB2 client support is compiled in.

Does Defensia detect CVE-2026-64385?

Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2026-64385 will appear in your dashboard with remediation steps.

Related Kernel CVEs

CVE-2026-64056CVSS 9.8In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Make RX SKB per-port The SKB used to assemble packets from fragments in gmac_rx() is static local, but the Gemini has two ethernet ports, meaning there can be races between the ports on a bad day if a device is using both. Make the RX SKB a per-port variable and carry it over between invocations in the port struct instead. Zero the pointer once we call napi_gro_frags(), on error (after calling napi_free_frags()) or if the port is stopped. Zero it in some place where not strictly necessary just to emphasize what is going on. This was found by Sashiko during normal patch review.
CVE-2026-64383CVSS 9.8In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_flush() replay SMB2_flush() keeps its response buffer bookkeeping across replay attempts. If a replayable flush response is received and the retry then fails before cifs_send_recv() stores a replacement response, flush_exit will free the stale response pointer a second time. Reinitialize resp_buftype and rsp_iov at the top of the replay loop so cleanup only acts on response state produced by the current attempt. This fixes a double-free without changing replay handling for successful requests.
CVE-2026-64055CVSS 9.8In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Carry over frag counter The gmac_rx() NAPI poll function assembles packets in an SKB from a ring buffer. If the ring buffer gets completely emptied during a poll cycle, we exit gmac_rx(), but the packet is not yet completely assembled in the SKB, yet the fragment counter frag_nr is reset to zero on the next invocation. Solve this by making the RX fragment counter a part of the port struct, and carry it over between invocations. Reset the fragment counter only right after calling napi_gro_frags(), on error (after calling napi_free_frags()) or if stopping the port. Reset it in some place where not strictly necessary just to emphasize what is going on. This was found by Sashiko during normal patch review.
CVE-2026-64384CVSS 9.8In the Linux kernel, the following vulnerability has been resolved: smb: client: fix change notify replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_notify_init() fails before the next send, cleanup retains the previous buffer type and frees that response again. Reset response bookkeeping before each attempt to prevent the stale free.
CVE-2026-64061CVSS 9.8In the Linux kernel, the following vulnerability has been resolved: netfs: Fix early put of sink folio in netfs_read_gaps() Fix netfs_read_gaps() to release the sink page it uses after waiting for the request to complete. The way the sink page is used is that an ITER_BVEC-class iterator is created that has the gaps from the target folio at either end, but has the sink page tiled over the middle so that a single read op can fill in both gaps. The bug was found by KASAN detecting a UAF on the generic/075 xfstest in the cifsd kernel thread that handles reception of data from the TCP socket: BUG: KASAN: use-after-free in _copy_to_iter+0x48a/0xa20 Write of size 885 at addr ffff888107f92000 by task cifsd/1285 CPU: 2 UID: 0 PID: 1285 Comm: cifsd Not tainted 7.0.0 #6 PREEMPT(lazy) Call Trace: dump_stack_lvl+0x5d/0x80 print_report+0x17f/0x4f1 kasan_report+0x100/0x1e0 kasan_check_range+0x10f/0x1e0 __asan_memcpy+0x3c/0x60 _copy_to_iter+0x48a/0xa20 __skb_datagram_iter+0x2c9/0x430 skb_copy_datagram_iter+0x6e/0x160 tcp_recvmsg_locked+0xce0/0x1130 tcp_recvmsg+0xeb/0x300 inet_recvmsg+0xcf/0x3a0 sock_recvmsg+0xea/0x100 cifs_readv_from_socket+0x3a6/0x4d0 [cifs] cifs_read_iter_from_socket+0xdd/0x130 [cifs] cifs_readv_receive+0xaad/0xb10 [cifs] cifs_demultiplex_thread+0x1148/0x1740 [cifs] kthread+0x1cf/0x210

References

Track CVEs across your fleet automatically

Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-64385. Free for 1 server.

Get started free