Executive brief
A vulnerability in the Linux kernel's SMB client allows a malicious server to read sensitive information from the computer's memory. By sending a specially crafted response to a file information request, a server can trick the client into exposing adjacent data from the system's kernel heap. This could lead to the theft of sensitive data or credentials from the affected system.
Technical details
The vulnerability exists in the smb2_ioctl_query_info() function within the Linux kernel's SMB client. The QUERY_INFO path fails to verify that the flexible-array payload in the server's response actually fits within the allocated response buffer (rsp_iov[1].iov_len) before copying it to userspace. A malicious server can provide an OutputBufferLength value larger than the actual response, causing copy_to_user() to read past the intended buffer and leak adjacent kernel heap memory. The fix introduces a bounds check using struct_size() to ensure the payload fits within the buffer and to prevent integer overflows on 32-bit systems.
Affected products
- Linux Linux Kernel 5.1 to 6.6.136, 6.7 to 6.12.84, 6.13 to 6.18.25, 6.19 to 7.0.2
Timeline
- 2026-05-01: advisory: Initial disclosure of CVE-2026-31708
- 2026-04-27: patched: Fixes committed to various stable kernel branches
References
- https://git.kernel.org/stable/c/078fae8f50adebb903ccf2252b44391324571e78
- https://git.kernel.org/stable/c/1dd757379997b71a328a4b591ffaf481acd0ead1
- https://git.kernel.org/stable/c/85fd46ee26a11841c670449508025965f61ce131
- https://git.kernel.org/stable/c/a34d456934fe42e4da5d2cc07787bf418bee99c6
- https://git.kernel.org/stable/c/a58c5af19ff0d6f44f6e9fe31e33a2c92223f77e
- https://git.kernel.org/stable/c/ac2f14e4705d020f04e806efa0d49ab8dc2b145f