CVE-2026-31705 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: May 3, 2026
Linux Kernel ksmbd - Out-of-Bounds Write
Published: May 1, 2026Updated: May 3, 2026Remote Exploitable
Overview
Linux kernel ksmbd contains an out-of-bounds write vulnerability caused by missing bounds check on 4-byte alignment padding in smb2_get_ea(), letting attackers potentially overwrite adjacent kernel heap memory, exploit requires crafted compound SMB requests.
Severity & Score
Severity: Critical
CVSS Score: 9.8
Impact
Attackers can cause out-of-bounds write, potentially leading to kernel memory corruption or system instability.
Mitigation
Update to the latest Linux kernel version containing the fix for this vulnerability.
References
- https://git.kernel.org/stable/c/922d48fe8c19f388ffa2f709f33acaae4e408de2
- https://git.kernel.org/stable/c/98f3de6ef4efbd899348d333f0902dc4ff14380c
- https://git.kernel.org/stable/c/ffbce350c6fd1e99116ea57383b9031717e36d3b
- https://git.kernel.org/stable/c/30010c952077a1c89ecdd71fc4d574c75a8f5617
- https://git.kernel.org/stable/c/790304c02bf9bd7b8171feda4294d6e62d32ae8f
Related Resources
Details
- CVE ID
- CVE-2026-31705
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- out_of_bounds_rw
- Status
- unconfirmed
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H