CVE-2026-64136
CRITICAL
Published Jul 19, 2026
Modified Jul 20, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() Commit 96c4af418586 ("cifs: Fix locking usage for tcon fields") refactored cifs code to change cifs_tcp_ses_lock for tc_lock around tc_count changes. There was missing lock around tc_count increment inside smb2_find_smb_sess_tcon_unlocked().
Is your site exposed to CVE-2026-64136?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — Exploit Prediction
0.0050
Probability of exploitation
0.39%
Percentile rank
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
References
Other References
https://git.kernel.org/stable/c/13fb413ae22a37c69341918a6d651d19a9b0b9b7
https://git.kernel.org/stable/c/4d8690dace005a38e6dbde9ecce2da3ad85c7c41
https://git.kernel.org/stable/c/7df1df6f40c0720d30206aa35c0343b962350e0d
https://git.kernel.org/stable/c/bf4ebdb19ff9b3cdf992b50715fe61633327416a
https://git.kernel.org/stable/c/e374f4e496fef8168784f93a4477d67be34485fd
Frequently Asked Questions
What is CVE-2026-64136? +
In the Linux kernel, the following vulnerability has been resolved:
smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked()
Commit 96c4af418586 ("cifs: Fix locking usage for tcon fields")
refactored cifs code to change cifs_tcp_ses_lock for tc_lock around
tc_count changes.
There was missing lock around tc_count increment inside
smb2_find_smb_sess_tcon_unlocked(). It has a CVSS v3.1 base score of 9.8 (CRITICAL).
How severe is CVE-2026-64136? +
CVE-2026-64136 has a CVSS v3.1 score of 9.8 out of 10, rated CRITICAL. This is a critical vulnerability that should be patched immediately. The EPSS score is 0.0050, placing it in the 0th percentile for exploitation probability.
How do I check if I'm vulnerable to CVE-2026-64136? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.