VYPR
Critical severity9.8NVD Advisory· Published Jul 25, 2026· Updated Sep 4, 2026

CVE-2026-64386

CVE-2026-64386

Description

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix query_info() replay double-free

A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_query_info_init() fails before the next send, cleanup retains the previous buffer type and frees that response again.

Reset response bookkeeping before each attempt to prevent the stale free.

Affected products

78

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.