CVE-2026-64382
Published Jul 25, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_open() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_open_init() fails before the next send, cleanup retains the previous buffer type and frees that response again. Reset response bookkeeping before each attempt to prevent the stale free.
Is your site exposed to CVE-2026-64382?
Run a free security scan — no signup, results in seconds.
EPSS — Exploit Prediction
0.0021
Probability of exploitation
0.11%
Percentile rank
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
References
Other References
https://git.kernel.org/stable/c/02bc2896bdc3e29362d6e40d404006944a159c25
https://git.kernel.org/stable/c/14498ff5ce0f272ce0ef988721413e06b7038972
https://git.kernel.org/stable/c/3196b5192f246df4272072f61a2f4a3e9967f55d
https://git.kernel.org/stable/c/b55e182f2324bc6a604c21a47aa6c448f719a532
https://git.kernel.org/stable/c/ff2d30927bc3bf3c629f0768d2068096e64ef5ce
Frequently Asked Questions
What is CVE-2026-64382? +
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix double-free in SMB2_open() replay
A response-bearing attempt can return a replayable error and free its
response buffer. If SMB2_open_init() fails before the next send, cleanup
retains the previous buffer type and frees that response again.
Reset response bookkeeping before each attempt to prevent the stale free.
How do I check if I'm vulnerable to CVE-2026-64382? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.