Multiple CVEs Address UAF Vulnerabilities in SMB Client
First seen 18 Feb 2026, 09:15 UTC
•
•47
Export
Article Content
Browse articles
Two vulnerabilities in the SMB client have been addressed, specifically CVE-2025-37750 and CVE-2024-26928. CVE-2025-37750, published on May 1, 2025, fixes a use-after-free (UAF) issue in decryption with multichannel, while CVE-2024-26928, published on April 28, 2024, addresses a potential UAF in the cifs_debug_files_proc_show() function. Affected systems include those utilizing the SMB client in Microsoft environments.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2024-04-28
CVE-2024-26928 published
2025-05-01
CVE-2025-37750 published
2026-02-18
Information published on both CVEs