Kernel-level SMB/CIFS bug affects Linux kernels broadly; high CVSS and potential kernel compromise makes this widely impactful across organizations.
CVE-2026-64136
Linux kernel CIFS/SMB client race corrupts refcount, risking kernel compromise.
Is CVE-2026-64136 being exploited?
Not confirmed. CVE-2026-64136 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.49% probability of exploitation in the next 30 days.
How severe is CVE-2026-64136?
CVE-2026-64136 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-64136?
Yes. A fix has been recorded for CVE-2026-64136. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-64136 affect?
CVE-2026-64136 affects Linux kernel (CIFS/SMB client), Linux distributions with affected kernels. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-64136?
Apply vendor kernel updates or backport commit; disable SMB client until patched.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Race in tc_count increment can corrupt reference counts causing use-after-free, kernel memory corruption leading to privilege escalation or DoS.
Immediate action required
- affected>= 953953abb66e52c224057ab91e404284fefeab62 and < 7df1df6f40c0720d30206aa35c0343b962350e0d
- affected>= 601dd3b79769b38d30b693c40afdb2a4b7edf9d0 and < 13fb413ae22a37c69341918a6d651d19a9b0b9b7
- affected>= 3969db6b22e3d90d8c5f22ac1a7fe0350a94c136 and < bf4ebdb19ff9b3cdf992b50715fe61633327416a
- affected>= 96c4af418586ee9a6aab61738644366426e05316 and < e374f4e496fef8168784f93a4477d67be34485fd
- affected>= 96c4af418586ee9a6aab61738644366426e05316 and < 4d8690dace005a38e6dbde9ecce2da3ad85c7c41
- affected8c59eeeeffa1524ef57e173a89a1a3ff539888d5
- affected>= 6.6.128 and < 6.6.142
- affected>= 6.12.75 and < 6.12.92
- affected>= 6.18.16 and < 6.18.34
- affected>= 6.19.6 and < 6.20
- affected7.0
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.