PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-31392 Linux CVE debrief

A session reuse flaw in the Linux kernel SMB client (CIFS) allows Kerberos-authenticated mounts to incorrectly reuse SMB sessions from prior mounts, even when a different username= option is specified. This can cause unauthorized access to shares using credentials from a previous mount, or cause mount failures when the wrong principal is used. The vulnerability exists because match_session() did not consider the username mount option when Kerberos (sec=krb5) was in use. Patches are available for multiple stable kernel branches.

Vendor
Linux
Product
Unknown
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-03
Original CVE updated
2026-07-21
Advisory published
2026-04-03
Advisory updated
2026-07-21

Who should care

Linux system administrators using CIFS mounts with Kerberos authentication, particularly in multi-user or automated mounting environments where different credentials may be specified for different shares. Organizations with strict access controls on SMB shares where credential isolation between mounts is security-critical.

Technical summary

The Linux kernel's SMB client (fs/smb/client) contains a flaw in match_session() where the username mount option was not considered during session matching for Kerberos-authenticated mounts (sec=krb5). When multiple mounts are performed against the same server with different username= options, the client incorrectly reuses the existing SMB session from the first mount instead of establishing a new session with the specified credentials. This occurs because session matching logic only validated server address and port, not the username principal. The vulnerability affects kernel versions from 2.6.32.44 through 6.19.10 and 7.0-rc1 through rc4. Patches add username matching to match_session() for Kerberos sessions, ensuring distinct sessions are established for distinct principals.

Defensive priority

HIGH

Recommended defensive actions

  • Apply kernel patches from stable branches: 6.1.167+, 6.6.130+, 6.12.78+, 6.18.20+, 6.19.10+, or 7.0-rc5+
  • Verify kernel version matches or exceeds patched versions for your LTS branch
  • If immediate patching is not possible, avoid concurrent krb5 mounts with different username= options on the same client
  • Audit existing CIFS mount configurations for username= usage with sec=krb5
  • Review SMB session establishment logs for unexpected credential reuse

Evidence notes

CVE description confirms the vulnerability is in the Linux kernel SMB client, specifically in session matching logic. The fix modifies match_session() to include username in session matching for Kerberos mounts. CVSS 8.1 (HIGH) with vector AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L indicates local attack vector with high privileges required but significant impact. Not listed in CISA KEV.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-31392 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-31392

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-31392 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-31392

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/12b4c5d98cd7ca46d5035a57bcd995df614c14e1

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/6e9ff1eb7feedcf46ff2d0503759960ab58e7775

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/9229709ec8bf85ae7ca53aeee9aa14814cdc1bd2

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/9ee803bfdba0cf739038dbdabdd4c02582c8f2b2

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/d33cbf0bf8979d779900da9be2505d68d9d8da25

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/fd4547830720647d4af02ee50f883c4b1cca06e4

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.