Junglewise Threat Intelligence

CVE-2026-31476: Linux Kernel ksmbd denial of service via session binding failure

CVE-2026-31476 · Severity: high · CVSS 8.2 · Published 2026-04-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's SMB file-sharing server (ksmbd) allows an unauthenticated remote attacker to disconnect active users. By sending a specially crafted connection request with an incorrect password, the attacker can force the server to terminate legitimate user sessions. This results in a denial-of-service condition where users are unexpectedly kicked off the file server.

Technical details

A denial-of-service vulnerability exists in the ksmbd module of the Linux kernel due to improper session state management during SMB2 multichannel binding. When a session binding request fails (e.g., due to an invalid password), the error handling path in `fs/smb/server/smb2pdu.c` (or `fs/ksmbd/smb2pdu.c` in older versions) unconditionally sets the session state to `SMB2_SESSION_EXPIRED`. Because the binding process looks up existing sessions belonging to other connections via `ksmbd_session_lookup_slowpath()`, an attacker can target and invalidate any active session by providing its session ID in a failed binding attempt. This allows a remote, unauthenticated attacker to terminate arbitrary active sessions. The issue has been resolved by ensuring session expiration is skipped if the failed request was a binding attempt.

Affected products

  • Linux Linux Kernel 5.15.1 to 6.1.168, 6.2 to 6.6.131, 6.7 to 6.12.80, 6.13 to 6.18.21, 6.19 to 6.19.11

Timeline

  • 2026-03-17: other: Patch authored
  • 2026-04-22: advisory: CVE published
  • 2026-06-01: patched: Final stable tree updates applied

References

Related threats