High severity7.8NVD Advisory· Published Jul 25, 2026· Updated Sep 8, 2026
CVE-2026-64381
CVE-2026-64381
Description
In the Linux kernel, the following vulnerability has been resolved:
smb: client: Fix next buffer leak in receive_encrypted_standard()
receive_encrypted_standard() allocates next_buffer before checking whether the number of compound PDUs already reached MAX_COMPOUND. If the limit check fails, the function returns immediately and the newly allocated next_buffer is not assigned to server->smallbuf/server->bigbuf, making it leaked.
Move the MAX_COMPOUND check before allocating next_buffer.
Affected products
3- osv-coords2 versions
>= 4.19.0, < 5.10.261+ 1 more
- (no CPE)range: >= 4.19.0, < 5.10.261
- (no CPE)range: < 7.1.7-1.1
Patches
Vulnerability mechanics
References
8- git.kernel.org/stable/c/07e0ab81df1790afa35732a4e8e07ff831b29008nvdPatch
- git.kernel.org/stable/c/1c6267a1d5cf4c73b656f8181b310cbbb3e4767bnvdPatch
- git.kernel.org/stable/c/297243e365fc9fe2f8e9b7dd535a65d922cd108bnvdPatch
- git.kernel.org/stable/c/67097772df7791c53d608f04bd31c676ccf79b83nvdPatch
- git.kernel.org/stable/c/68fc0b6cc03ca58060c0f36454e169f5fe258974nvdPatch
- git.kernel.org/stable/c/9136a08dc29328edd9867f2545e73906ac9df93bnvdPatch
- git.kernel.org/stable/c/927d4805aea0a287d36dd4f826ee24d69a2afee3nvdPatch
- git.kernel.org/stable/c/94e4f672db029414b9888b5137a7559f1febf2d8nvdPatch
News mentions
1- Linux Kernel: 25 Vulnerabilities Across Subsystems Disclosed and Patched TogetherVypr Intelligence · Jul 26, 2026