CVE-2026-64136: Linux Kernel

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() Commit 96c4af418586 ("cifs: Fix locking usage for tcon fields") refactored cifs code to change cifs_tcp_ses_lock for tc_lock around tc_count changes. There was missing lock around tc_count increment inside smb2_find_smb_sess_tcon_unlocked().

Affected products

  • Linux Linux Kernel: from 6.6.128, before 6.6.142 (fixed in 6.6.142); from 6.12.75, before 6.12.92 (fixed in 6.12.92); from 6.18.16, before 6.18.34 (fixed in 6.18.34); from 6.19.6, before 7.0.11 (fixed in 7.0.11); version 7.1 only

Published 2026-07-19. Last modified 2026-08-13.