GHSA-4vgx-hp6g-jmm8CriticalCVSS 9.8

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free...

Published
August 6, 2026
Last Modified
August 8, 2026

🔗 CVE IDs covered (1)

📋 Description

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix double-free in SMB2_close() replay

A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_close_init() fails before the next send, cleanup retains the previous buffer type and frees that response again.

Reset response bookkeeping before each attempt to prevent the stale free.

🔗 References (7)