PatchSiren cyber security CVE debrief
CVE-2026-31410 Linux CVE debrief
CVE-2026-31410 is a Linux kernel ksmbd issue in the way FS_OBJECT_ID_INFORMATION is populated. The fix changes ksmbd to use the filesystem UUID from sb->s_uuid as the primary volume identifier, and to fall back to the statfs filesystem ID only when a UUID is unavailable. NVD rates the issue CVSS 5.5 (MEDIUM) with local attack prerequisites and high availability impact.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-06
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-06
- Advisory updated
- 2026-07-24
Who should care
Linux kernel maintainers, distribution security teams, and administrators running the ksmbd SMB server on affected Linux kernel releases. Organizations that expose SMB services from Linux kernels in the affected ranges should prioritize kernel update planning.
Technical summary
NVD’s record and the referenced kernel patches indicate that ksmbd was not using the preferred volume identifier when answering FS_OBJECT_ID_INFORMATION. The resolved change makes the kernel use sb->s_uuid first, which is the proper volume UUID when available, and otherwise derive an ID from vfs_statfs() (stfs.f_fsid). NVD lists affected Linux kernel ranges including 5.15 before 6.12.78, 6.13 before 6.18.20, 6.19 before 6.19.10, and 7.0-rc1 through 7.0-rc4.
Defensive priority
Medium. This is not marked KEV, but it affects a network file-sharing service path in the kernel and NVD rates the impact as high availability. Apply the kernel fix promptly on systems that run ksmbd.
Recommended defensive actions
- Update to a Linux kernel release that includes the referenced ksmbd fix.
- If you maintain a downstream kernel, backport the stable patch referenced by NVD.
- Review systems that expose ksmbd and confirm they are on a non-vulnerable kernel line.
- Track the affected version ranges in NVD when planning upgrades: 5.15 before 6.12.78, 6.13 before 6.18.20, and 6.19 before 6.19.10.
- Validate whether any deployed kernels match the listed 7.0 release candidates and update if they do.
Evidence notes
Source corpus support is limited to the NVD record and the linked kernel patches. The NVD description states the fix: use sb->s_uuid as the primary volume identifier, falling back to stfs.f_fsid from vfs_statfs() if no UUID exists. NVD marks the vuln status as Analyzed and provides four stable kernel patch references. CVSS in the supplied record is 5.5/MEDIUM with vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-31410 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-31410
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-31410 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-31410
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/3a64125730cabc34fccfbc230c2667c2e14f7308
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/3d80ebe6d1b7bc9ad20fd9b0c1a0c56d804f8a0a
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/c283a6ffe6d5d6e5594d991286b9ce15951572e1
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/ce00616bc1df675bfdacc968f2bf7c51f4669227
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.