Review reviewCritical

CVE-2026-64136

Linux

In the Linux kernel, the following vulnerability has been resolved: smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() Commit 96c4af418586 ("cifs: Fix locking usage for tcon fields") refactored cifs code to change cifs_tcp_ses_lock for tc_lock around tc_count changes. There was missing lock around tc_count increment inside smb2_find_smb_sess_tcon_unlocked().

CVSS
9.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.07.20
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 9.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() Commit 96c4af418586 ("cifs: Fix locking usage for tcon fields") refactored cifs code to change cifs_tcp_ses_lock for tc_lock around tc_count changes. There was missing lock around tc_count increment inside smb2_find_smb_sess_tcon_unlocked().

Affected product and versions

Product
Linux
Affected versions
>= 953953abb66e52c224057ab91e404284fefeab62 < 7df1df6f40c0720d30206aa35c0343b962350e0d, >= 601dd3b79769b38d30b693c40afdb2a4b7edf9d0 < 13fb413ae22a37c69341918a6d651d19a9b0b9b7, >= 3969db6b22e3d90d8c5f22ac1a7fe0350a94c136 < bf4ebdb19ff9b3cdf992b50715fe61633327416a, >= 96c4af418586ee9a6aab61738644366426e05316 < e374f4e496fef8168784f93a4477d67be34485fd, >= 96c4af418586ee9a6aab61738644366426e05316 < 4d8690dace005a38e6dbde9ecce2da3ad85c7c41, >= 8c59eeeeffa1524ef57e173a89a1a3ff539888d5, >= 6.6.128 < 6.6.142, >= 6.12.75 < 6.12.92, >= 6.18.16 < 6.18.34, >= 6.19.6 < 6.20, >= 7.0
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
Not available
CVE-2026-64136 — Linux | SECUFOCUS NOW