Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2026-64597

CVE-2026-64597: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityHigh7.0

    High [CVE-2026-64597] fix double-free in SMB2_close replay

    CVE-2026-64597Source published Source updated

    In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_close_init() fails before the next send, cleanup retains the previous buffer type and frees that response again. Reset response bookkeeping before each attempt to prevent the stale free. This double-free condition can lead to memory corruption, potentially resulting in a denial of service or the execution of arbitrary code. A double-free vulnerability exists in the SMB2_close() replay mechanism where a response buffer's bookkeeping state can become stale across retry attempts, leading to the same buffer being freed twice. This could result in memory corruption, potentially…

    Affected products in this advisory
    • Red Hat Enterprise Linux 10
    • Red Hat Enterprise Linux 9
    • Red Hat Enterprise Linux for NVIDIA 26
    • Red Hat package: kernel-rt
    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    • kernel-0:6.12.0-211.52.1.el10_2
    • kernel-0:5.14.0-687.46.1.el9_8
    • RHSA-2026:64775
    • RHSA-2026:66180
    Mitigation guidance
    • If SMB/CIFS client functionality is not required, the 'cifs' kernel module can be blocklisted to prevent it from loading. Systems that do not mount SMB/CIFS shares are not affected. For systems that require SMB client access, ensure connections are only made to trusted SMB servers.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery