CVE-2026-64142
A race condition in the Linux kernel's SMB server (ksmbd) durable handle scavenger can corrupt lists and cause use‑after‑free conditions, potentially allowing an attacker to execute arbitrary code, cause a denial of service, or escalate privileges. The flaw has been fixed in the Linux kernel by changing how durable handles are scavenged and reference counted.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux systems running the affected ksmbd SMB server component.
Real-world impact
Successful exploitation could lead to code execution, system crashes, or privilege escalation.
Why this severity
The CVSS v3.1 base score is 9.8 (Critical) because the vulnerability is network‑reachable, requires low attack complexity, no privileges or user interaction, and impacts confidentiality, integrity, and availability at the highest level.
What to do about it
- 011. Check the currently running Linux kernel version on your system.
- 022. Obtain and install the latest kernel update from your Linux distribution that includes the fix for CVE-2026-64142.
- 033. Reboot the system to load the updated kernel.
- 044. After reboot, verify the kernel version to confirm the fix is applied.
NVD-referenced vendor advisory (Linux kernel patch)
Timeline
- Jul 19, 2026 · 14d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 13d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 30, 2026 · 3d agoAdvisory updatedThe NVD record was last revised.