PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-31433 Linux CVE debrief

CVE-2026-31433 is a Linux kernel ksmbd issue in FILE_ALL_INFORMATION handling for compound SMB requests. According to the published description, a QUERY_DIRECTORY followed by QUERY_INFO can leave too little room in the response buffer, yet get_file_all_info() still attempted to convert and copy the filename as if PATH_MAX space were available. That can lead to an out-of-bounds write and potential memory corruption. The described fix adds an output-buffer-size check and bounds the filename conversion to the actual remaining space.

Vendor
Linux
Product
Unknown
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-22
Original CVE updated
2026-04-27
Advisory published
2026-04-22
Advisory updated
2026-04-27

Who should care

Administrators and security teams running Linux systems with ksmbd enabled should prioritize this, especially where SMB service is exposed to untrusted clients. Kernel maintainers and distro patch managers should also track the fix status in their supported branches.

Technical summary

The vulnerability is in ksmbd’s get_file_all_info() path for compound SMB2 requests. If an earlier request in the compound consumes nearly all of max_trans_size, the code could still call smbConvertToUTF16() using PATH_MAX rather than the actual free space in the output buffer. The result is an out-of-bounds write beyond the response buffer. The described remediation computes the remaining output-buffer capacity with smb2_calc_max_out_buf_len(), returns -EINVAL when the buffer is insufficient, and limits smbConvertToUTF16() to the real filename length, clamped by PATH_MAX.

Defensive priority

High. The CVSS vector provided by the source is AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, which indicates network reachability, low privileges, no user interaction, and high impact if successfully triggered.

Recommended defensive actions

  • Verify whether ksmbd is enabled on any Linux systems you operate.
  • Check vendor kernel advisories or stable kernel updates that include the ksmbd fix for CVE-2026-31433.
  • Prioritize patching systems that expose SMB service to untrusted networks or tenants.
  • If immediate patching is not possible, reduce exposure by limiting SMB access to trusted networks and authenticated clients.
  • Monitor logs for unusual SMB compound request patterns targeting ksmbd until systems are updated.

Evidence notes

This debrief is based only on the supplied NVD record and the kernel-stable commit references listed there. The NVD entry is marked "Undergoing Analysis" and does not provide affected version ranges in the supplied corpus. Vendor attribution is treated as Linux kernel/ksmbd based on the vulnerability description; no broader product scope is asserted. The KEV field is false in the provided data.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-31433 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-31433

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-31433 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-31433

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/358cdaa1f7fbf2712cb4c5f6b59cb9a5c673c5fe

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/3a852f9d1c981fb14f6bf4e24999e0ea8088a7d7

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/4cca3eff2099b18672934a39cee70aed835d652c

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/7aec5a769d2356cbf344d85bcfd36de592ac96a5

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/9d7032851d6f5adbe2739601ca456c0ad3b422f0

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b0cd9725fe2bcc9f37d096b132318a9060373f5d

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/beef2634f81f1c086208191f7228bce1d366493d

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.