CVE-2026-64396 | Linux Kernel up to 7.1.3 ksmbd request_lock/llist use after free

SecurityVulns

A vulnerability classified as very critical was found in Linux Kernel up to 6.1.177/6.6.144/6.12.95/6.18.38/7.1.3. Affected by this issue is the function smb2_remove_blocked_lock/ksmbd_vfs_posix_lock_wait of the component ksmbd. The manipulation of the argument request_lock/llist results in use after free.

This vulnerability was named CVE-2026-64396. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is advised.VulDB Recent EntriesRead More