Junglewise Threat Intelligence

CVE-2026-31705: Linux Kernel ksmbd out-of-bounds write in smb2_get_ea

CVE-2026-31705 · Severity: critical · CVSS 9.8 · Published 2026-05-01

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's ksmbd component, which provides file-sharing services over a network. An attacker can exploit this flaw to overwrite system memory, potentially leading to a complete system crash or unauthorized access to sensitive data. This issue occurs when the system processes specific types of file information requests that exceed the allocated memory buffer.

Technical details

An out-of-bounds (OOB) write vulnerability exists in the ksmbd module of the Linux kernel within the smb2_get_ea() function. The root cause is an unconditional memset() operation used for 4-byte alignment padding that fails to verify if sufficient space remains in the response buffer (buf_free_len). In scenarios involving compound SMB2 requests, a preceding command may consume most of the shared response buffer, leaving insufficient space for the QUERY_INFO EA response's padding. This results in 1-3 NUL bytes being written past the kvmalloc-allocated boundary into adjacent kernel heap memory. The vulnerability is reachable over the network without authentication if ksmbd is active. Patches have been released across multiple stable kernel branches to add the necessary bounds checks.

Affected products

  • Linux Linux Kernel 5.15.145 to 5.16, 6.1.71 to 6.2, 6.6 to 6.6.136, 6.7 to 6.12.84, 6.13 to 6.18.25, 6.19 to 7.0.2

Timeline

  • 2026-04-17: other: Vulnerability fixed in kernel source by Tristan Madani
  • 2026-05-01: disclosed: CVE-2026-31705 published
  • 2026-05-01: advisory

References

Related threats