CVE-2026-64257
A flaw in the Linux kernel’s SMB2 client handling could let an attacker send crafted responses that overlap data areas, causing the kernel to misinterpret the response length. The bug was fixed by restricting the length exception to responses without data and rejecting overlapping responses. The issue is critical because it can be triggered over the network without any user interaction.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
All Linux kernel versions that do not yet include the fix (commit 53b7c271f06b). Linux system administrators and users of affected distributions are the typical audience.
Real-world impact
An attacker could send specially crafted SMB2 responses to a vulnerable Linux system, potentially causing the kernel to crash or behave unpredictably, leading to a denial of service or other disruptions.
Why this severity
The CVSS score of 9.1 reflects that the vulnerability can be exploited remotely over the network, requires no special privileges or user interaction, and fully compromises confidentiality and availability of the affected system.
What to do about it
- 01Update the Linux kernel to a version that includes commit 53b7c271f06b or later.
NVD description
Timeline
- Jul 25, 2026 · 7d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 27, 2026 · 5d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 30, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.