CVE-2024-46736
A critical flaw in the Linux kernel’s SMB client caused a double release of a file reference, which could lead to memory corruption. The bug could allow attackers to crash the system or potentially take control. It has been fixed in recent kernel releases.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel users, especially those running kernel 6.11 or earlier, as the vulnerability affects the SMB client component.
Real-world impact
An attacker could crash the system or exploit memory corruption to gain control, leading to denial of service or unauthorized actions.
Why this severity
The CVSS score of 9.8 reflects that the flaw is network‑exploitable, requires no user interaction, and can compromise confidentiality, integrity, and availability.
What to do about it
- 01Upgrade your Linux kernel to version 6.11 or later.
- 02Reboot the system to load the new kernel.
NVD-referenced vendor advisory
Timeline
- Sep 18, 2024 · Sep 18, 2024PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 5, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.