Kernel SMB client bug affects widely deployed Linux kernels; kernel-level exploit can disrupt servers/endpoints and is broadly relevant to IT orgs.
CVE-2026-64257
Linux kernel SMB2 client accepts overlapping data areas allowing memory corruption.
Is CVE-2026-64257 being exploited?
Not confirmed. CVE-2026-64257 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.66% probability of exploitation in the next 30 days.
How severe is CVE-2026-64257?
CVE-2026-64257 is rated Critical with a CVSS score of 9.1. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-64257?
Yes. A fix has been recorded for CVE-2026-64257. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-64257 affect?
CVE-2026-64257 affects Linux kernel SMB client (SMB2), Linux distributions with affected kernels, Endpoints and servers using kernel SMB client. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-64257?
Apply vendor kernel updates immediately; block untrusted SMB servers and limit SMB client access.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Remote attacker (malicious SMB server or MITM) can send crafted SMB2 responses to cause memory corruption, crashes, potential data leakage or RCE.
Immediate action required
- affected>= 31c6312608c60b72a1feb99a5afb680645a3e8a3 and < 445ece263131780dee273d727a4d6f11934feec7
- affected>= 573e502d14714d2947e22e7eff40ec20a6a44a42 and < 36bfa52459e45c0d5b668de2f1c91f6dc5c67775
- affected>= 419ec1b604d7fb60c10aec2dc062371f9fcd4940 and < 4a9d2657d3e05f6ed09c148cb127b4e58702275f
- affected>= ceb875a375dedbf51c9425c1d13a2d7a8435c08c and < fdafa1e68dc75045b7b617e6e7d2854950804d83
- affected>= 6e9d10f62773b99bd927940fd9cbdfe7207e23ff and < 57cba95f0e97c6f6e45e6731da30aff091bd7460
- affected>= 53b7c271f06be4dd5cfc8c6ef552a8355c891a7f and < 8986c932905ea508d66da421eb2eb6e676ace1fe
- affected8d0bbc78046d264bbf6a574ea6f9072258a43e35
- affectedb6a381c01e2ac98a48e32ac0f2a45bbadd9e26b0
- affected>= 5.10.261 and < 5.11
- affected>= 5.15.212 and < 5.16
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.