Ghostwire

CVE-2026-64597: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay...

CRITICAL CVSS 0.0 EPSS 0.16%

Published: August 6, 2026 | Last Modified: August 6, 2026

Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_close_init() fails before the next send, cleanup retains the previous buffer type and frees that response again. Reset response bookkeeping before each attempt to prevent the stale free.

Ghostwire Analysis — What This Means Practically

Exploitation Probability (EPSS): Low — 0.16% (5th percentile)

Low exploitation probability based on current threat landscape data. Standard patching timeline is appropriate.

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References