CVE-2026-31432: Linux Kernel
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix OOB write in QUERY_INFO for compound requests When a compound request such as READ + QUERY_INFO(Security) is received, and the first command (READ) consumes most of the response buffer, ksmbd could write beyond the allocated buffer while building a security descriptor. The root cause was that smb2_get_info_sec() checked buffer space using ppntsd_size from xattr, while build_sec_desc() often synthesized a significantly larger descriptor from POSIX ACLs. This patch introduces smb_acl_sec_desc_scratch_len() to accurately compute the final descriptor size beforehand, performs proper buffer checking with smb2_calc_max_out_buf_len(), and uses exact-sized allocation + iov pinning.
Affected products
- Linux Linux Kernel: from 5.15.145, before 5.16 (fixed in 5.16); from 6.1.71, before 6.2 (fixed in 6.2); from 6.6, before 6.12.81 (fixed in 6.12.81); from 6.13, before 6.18.22 (fixed in 6.18.22); from 6.19, before 6.19.12 (fixed in 6.19.12); version 7.0 only
Published 2026-04-22. Last modified 2026-06-19.