CVE-2026-45972
9.8 CRITICALIn the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF and double free in smb2_open_file() ...
Published: 2026-05-27 · Last updated: 2026-05-30
Severity and scoring
- CVSS
- 9.8 CRITICAL
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF and double free in smb2_open_file() Zero out @err_iov and @err_buftype before retrying SMB2_open() to prevent an UAF bug if @data != NULL, otherwise a double free.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2026-45972
- [Other]https://git.kernel.org/stable/c/4d339b219004869e96c4ce56b8891f83a38da4c0
- [Other]https://git.kernel.org/stable/c/639deb962986ef2f5e2a6d5a600c66f922471e81
- [Other]https://git.kernel.org/stable/c/7425453ea16dbc3bbb0f6cac4d60b537e5e4d151
- [Other]https://git.kernel.org/stable/c/96e53bb3ee2f354cf6b4ab07bcc56e500f8b3f74
- [Other]https://git.kernel.org/stable/c/e66dcf7bb9c4df5582c82bc3582725abcbfbea73
- [Other]https://git.kernel.org/stable/c/ebbbc4bfad4cb355d17c671223d0814ee3ef4eda