CVE-2026-31478: Linux Kernel
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: ksmbd: replace hardcoded hdr2_len with offsetof() in smb2_calc_max_out_buf_len() After this commit (e2b76ab8b5c9 "ksmbd: add support for read compound"), response buffer management was changed to use dynamic iov array. In the new design, smb2_calc_max_out_buf_len() expects the second argument (hdr2_len) to be the offset of ->Buffer field in the response structure, not a hardcoded magic number. Fix the remaining call sites to use the correct offsetof() value.
Affected products
- Linux Linux Kernel: from 5.15.145, before 5.15.203 (fixed in 5.15.203); from 6.1.71, before 6.1.168 (fixed in 6.1.168); from 6.6.1, before 6.6.131 (fixed in 6.6.131); from 6.7, before 6.12.80 (fixed in 6.12.80); from 6.13, before 6.18.21 (fixed in 6.18.21); from 6.19, before 6.19.11 (fixed in 6.19.11); …
Published 2026-04-22. Last modified 2026-06-17.