Skip to content
major vulnerability· requires attention

Kernel SMB client bug affects widely deployed Linux kernels; kernel-level exploit can disrupt servers/endpoints and is broadly relevant to IT orgs.

Systems

CVE-2026-64257

9.1
Critical
EPSS 0.66%Patch availableJul 27, 2026

Linux kernel SMB2 client accepts overlapping data areas allowing memory corruption.

common questions

Is CVE-2026-64257 being exploited?

Not confirmed. CVE-2026-64257 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.66% probability of exploitation in the next 30 days.

How severe is CVE-2026-64257?

CVE-2026-64257 is rated Critical with a CVSS score of 9.1. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.

Is there a patch for CVE-2026-64257?

Yes. A fix has been recorded for CVE-2026-64257. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.

What does CVE-2026-64257 affect?

CVE-2026-64257 affects Linux kernel SMB client (SMB2), Linux distributions with affected kernels, Endpoints and servers using kernel SMB client. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.

What should I do about CVE-2026-64257?

Apply vendor kernel updates immediately; block untrusted SMB servers and limit SMB client access.

Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.

executive summary
technical analysis
affected
Linux kernel SMB client (SMB2)Linux distributions with affected kernelsEndpoints and servers using kernel SMB client
impact

Remote attacker (malicious SMB server or MITM) can send crafted SMB2 responses to cause memory corruption, crashes, potential data leakage or RCE.

action required

Immediate action required

affected versions
Linux Linux
  • affected>= 31c6312608c60b72a1feb99a5afb680645a3e8a3 and < 445ece263131780dee273d727a4d6f11934feec7
  • affected>= 573e502d14714d2947e22e7eff40ec20a6a44a42 and < 36bfa52459e45c0d5b668de2f1c91f6dc5c67775
  • affected>= 419ec1b604d7fb60c10aec2dc062371f9fcd4940 and < 4a9d2657d3e05f6ed09c148cb127b4e58702275f
  • affected>= ceb875a375dedbf51c9425c1d13a2d7a8435c08c and < fdafa1e68dc75045b7b617e6e7d2854950804d83
  • affected>= 6e9d10f62773b99bd927940fd9cbdfe7207e23ff and < 57cba95f0e97c6f6e45e6731da30aff091bd7460
  • affected>= 53b7c271f06be4dd5cfc8c6ef552a8355c891a7f and < 8986c932905ea508d66da421eb2eb6e676ace1fe
  • affected8d0bbc78046d264bbf6a574ea6f9072258a43e35
  • affectedb6a381c01e2ac98a48e32ac0f2a45bbadd9e26b0
  • affected>= 5.10.261 and < 5.11
  • affected>= 5.15.212 and < 5.16

As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.

how to fix
Remediation steps are tailored for users whose stack is affected. Add this technology to your stack to see the fix checklist.
references
get alerted

Track only the vulnerabilities that affect your infrastructure.

start for free