Impact
The Linux kernel’s SMB client contains a double‑free bug when a query directory operation receives a replayable error. The bug frees the same response buffer twice, resulting in memory corruption. The weakness is identified as CWE‑1341 (Improper Validation of Self‑Input).
Affected Systems
All Linux systems running a kernel that includes the SMB client implementation prior to the fixed commit are potentially affected. The CNA lists the vendor as Linux and the product as Linux kernel, but no specific version range is provided, so any kernel lacking the fix could be vulnerable.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. The EPSS score of <1% shows a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector is a malicious or faulty SMB server that triggers the replayable error, which could be used by an attacker who can communicate with the vulnerable client.
OpenCVE Enrichment
Debian DLA