Junglewise Threat Intelligence

CVE-2026-31432: Linux Kernel ksmbd out-of-bounds write in QUERY_INFO

CVE-2026-31432 · Severity: high · CVSS 8.8 · Published 2026-04-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's ksmbd module, which provides SMB file sharing services. When processing specific combined requests (such as reading a file and then querying its security information), the system may write data beyond its intended memory boundaries. This could allow an authenticated user to crash the system or potentially execute unauthorized code, impacting the server's stability and data security.

Technical details

An out-of-bounds (OOB) write vulnerability exists in the ksmbd (SMB server) implementation within the Linux kernel during the processing of QUERY_INFO compound requests. When a compound request (e.g., READ + QUERY_INFO) is received, the first command may consume a significant portion of the response buffer. The function smb2_get_info_sec() incorrectly validated buffer space using the size of the security descriptor from extended attributes (xattr), while build_sec_desc() could synthesize a much larger descriptor from POSIX ACLs. This discrepancy allows an attacker to trigger a write beyond the allocated response buffer. The fix involves accurately pre-calculating the descriptor size and implementing stricter buffer boundary checks.

Affected products

  • Linux Linux Kernel 5.15.145 to 5.16, 6.1.71 to 6.2, 6.6 to 6.12.81, 6.13 to 6.18.22, 6.19 to 6.19.12, 7.0-rc1 to 7.0-rc6

Timeline

  • 2026-04-22: advisory: Initial disclosure of CVE-2026-31432
  • 2026-04-22: patched: Fixes merged into various stable kernel branches

References

Related threats