PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-31410 Linux CVE debrief

CVE-2026-31410 is a Linux kernel ksmbd issue in the way FS_OBJECT_ID_INFORMATION is populated. The fix changes ksmbd to use the filesystem UUID from sb->s_uuid as the primary volume identifier, and to fall back to the statfs filesystem ID only when a UUID is unavailable. NVD rates the issue CVSS 5.5 (MEDIUM) with local attack prerequisites and high availability impact.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-06
Original CVE updated
2026-07-24
Advisory published
2026-04-06
Advisory updated
2026-07-24

Who should care

Linux kernel maintainers, distribution security teams, and administrators running the ksmbd SMB server on affected Linux kernel releases. Organizations that expose SMB services from Linux kernels in the affected ranges should prioritize kernel update planning.

Technical summary

NVD’s record and the referenced kernel patches indicate that ksmbd was not using the preferred volume identifier when answering FS_OBJECT_ID_INFORMATION. The resolved change makes the kernel use sb->s_uuid first, which is the proper volume UUID when available, and otherwise derive an ID from vfs_statfs() (stfs.f_fsid). NVD lists affected Linux kernel ranges including 5.15 before 6.12.78, 6.13 before 6.18.20, 6.19 before 6.19.10, and 7.0-rc1 through 7.0-rc4.

Defensive priority

Medium. This is not marked KEV, but it affects a network file-sharing service path in the kernel and NVD rates the impact as high availability. Apply the kernel fix promptly on systems that run ksmbd.

Recommended defensive actions

  • Update to a Linux kernel release that includes the referenced ksmbd fix.
  • If you maintain a downstream kernel, backport the stable patch referenced by NVD.
  • Review systems that expose ksmbd and confirm they are on a non-vulnerable kernel line.
  • Track the affected version ranges in NVD when planning upgrades: 5.15 before 6.12.78, 6.13 before 6.18.20, and 6.19 before 6.19.10.
  • Validate whether any deployed kernels match the listed 7.0 release candidates and update if they do.

Evidence notes

Source corpus support is limited to the NVD record and the linked kernel patches. The NVD description states the fix: use sb->s_uuid as the primary volume identifier, falling back to stfs.f_fsid from vfs_statfs() if no UUID exists. NVD marks the vuln status as Analyzed and provides four stable kernel patch references. CVSS in the supplied record is 5.5/MEDIUM with vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-31410 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-31410

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-31410 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-31410

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/3a64125730cabc34fccfbc230c2667c2e14f7308

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/3d80ebe6d1b7bc9ad20fd9b0c1a0c56d804f8a0a

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/c283a6ffe6d5d6e5594d991286b9ce15951572e1

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/ce00616bc1df675bfdacc968f2bf7c51f4669227

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.