PatchSiren cyber security CVE debrief
CVE-2026-31433 Linux CVE debrief
CVE-2026-31433 is a Linux kernel ksmbd issue in FILE_ALL_INFORMATION handling for compound SMB requests. According to the published description, a QUERY_DIRECTORY followed by QUERY_INFO can leave too little room in the response buffer, yet get_file_all_info() still attempted to convert and copy the filename as if PATH_MAX space were available. That can lead to an out-of-bounds write and potential memory corruption. The described fix adds an output-buffer-size check and bounds the filename conversion to the actual remaining space.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-22
- Original CVE updated
- 2026-04-27
- Advisory published
- 2026-04-22
- Advisory updated
- 2026-04-27
Who should care
Administrators and security teams running Linux systems with ksmbd enabled should prioritize this, especially where SMB service is exposed to untrusted clients. Kernel maintainers and distro patch managers should also track the fix status in their supported branches.
Technical summary
The vulnerability is in ksmbd’s get_file_all_info() path for compound SMB2 requests. If an earlier request in the compound consumes nearly all of max_trans_size, the code could still call smbConvertToUTF16() using PATH_MAX rather than the actual free space in the output buffer. The result is an out-of-bounds write beyond the response buffer. The described remediation computes the remaining output-buffer capacity with smb2_calc_max_out_buf_len(), returns -EINVAL when the buffer is insufficient, and limits smbConvertToUTF16() to the real filename length, clamped by PATH_MAX.
Defensive priority
High. The CVSS vector provided by the source is AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, which indicates network reachability, low privileges, no user interaction, and high impact if successfully triggered.
Recommended defensive actions
- Verify whether ksmbd is enabled on any Linux systems you operate.
- Check vendor kernel advisories or stable kernel updates that include the ksmbd fix for CVE-2026-31433.
- Prioritize patching systems that expose SMB service to untrusted networks or tenants.
- If immediate patching is not possible, reduce exposure by limiting SMB access to trusted networks and authenticated clients.
- Monitor logs for unusual SMB compound request patterns targeting ksmbd until systems are updated.
Evidence notes
This debrief is based only on the supplied NVD record and the kernel-stable commit references listed there. The NVD entry is marked "Undergoing Analysis" and does not provide affected version ranges in the supplied corpus. Vendor attribution is treated as Linux kernel/ksmbd based on the vulnerability description; no broader product scope is asserted. The KEV field is false in the provided data.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-31433 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-31433
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-31433 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-31433
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/358cdaa1f7fbf2712cb4c5f6b59cb9a5c673c5fe
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/3a852f9d1c981fb14f6bf4e24999e0ea8088a7d7
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/4cca3eff2099b18672934a39cee70aed835d652c
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/7aec5a769d2356cbf344d85bcfd36de592ac96a5
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/9d7032851d6f5adbe2739601ca456c0ad3b422f0
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/b0cd9725fe2bcc9f37d096b132318a9060373f5d
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/beef2634f81f1c086208191f7228bce1d366493d
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.