CVE-2026-64597
CVE-2026-64597: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityHigh7.0
High [CVE-2026-64597] fix double-free in SMB2_close replay
CVE-2026-64597Source published Source updated
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_close_init() fails before the next send, cleanup retains the previous buffer type and frees that response again. Reset response bookkeeping before each attempt to prevent the stale free. This double-free condition can lead to memory corruption, potentially resulting in a denial of service or the execution of arbitrary code. A double-free vulnerability exists in the SMB2_close() replay mechanism where a response buffer's bookkeeping state can become stale across retry attempts, leading to the same buffer being freed twice. This could result in memory corruption, potentially…
- Affected products in this advisory
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 9
- Red Hat Enterprise Linux for NVIDIA 26
- Red Hat package: kernel-rt
- Source-reported affected versions
- Affected-version details not available in this record.
- Source-reported fixed versions
- kernel-0:6.12.0-211.52.1.el10_2
- kernel-0:5.14.0-687.46.1.el9_8
- RHSA-2026:64775
- RHSA-2026:66180
- Mitigation guidance
- If SMB/CIFS client functionality is not required, the 'cifs' kernel module can be blocklisted to prevent it from loading. Systems that do not mount SMB/CIFS shares are not affected. For systems that require SMB client access, ensure connections are only made to trusted SMB servers.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.