PatchSiren cyber security CVE debrief
CVE-2026-31709 Linux CVE debrief
CVE-2026-31709 is a Linux kernel SMB/CIFS client vulnerability involving incomplete validation of server-supplied DACL data before chmod/chown security-descriptor rewriting. NVD rates it 8.8 HIGH, and the published record indicates Linux kernel versions from 5.12 through before 7.0.2 are affected.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-01
- Original CVE updated
- 2026-07-15
- Advisory published
- 2026-05-01
- Advisory updated
- 2026-07-15
Who should care
Linux distribution maintainers, kernel and CIFS/SMB client maintainers, and administrators running affected Linux kernels that connect to untrusted or semi-trusted SMB servers should prioritize this issue. Security teams should pay special attention to systems that routinely mount network shares or automate permission changes on SMB-backed files.
Technical summary
The issue is in the Linux kernel SMB client path that handles ACL/DACL data from a server. According to the supplied description, build_sec_desc() and id_mode_to_cifs_acl() derive a DACL pointer from a server-controlled offset and then use the incoming ACL to rebuild the chmod/chown security descriptor. The original fix validated only the DACL header fields, but not the full DACL body; a truncated DACL could still claim ACEs and cause rewrite helpers such as replace_sids_and_copy_aces() or set_chmod_dacl() to walk beyond the validated extent. The described fix factors structural checks into validate_dacl(), extends validation to each ACE, and reuses that validator for both parse_dacl() and the rewrite paths.
Defensive priority
High. This is a network-reachable kernel flaw with a high CVSS score and potential impact on confidentiality, integrity, and availability when the SMB client processes malicious server responses. Prioritize patching or backporting the kernel fix on systems that access untrusted SMB servers.
Recommended defensive actions
- Apply the upstream or vendor kernel fix that strengthens DACL validation in the SMB/CIFS client.
- Backport the patch to supported kernel branches used in your environment, especially if you are running Linux kernel versions 5.12 through before 7.0.2.
- Review systems that mount SMB shares from untrusted or externally managed servers and schedule expedited maintenance for them.
- If immediate patching is not possible, reduce exposure by limiting SMB server trust relationships and restricting where chmod/chown operations are performed on SMB-mounted files.
- Verify that your vulnerability management process tracks the affected kernel range and the CVSS 8.8 HIGH rating for remediation prioritization.
Evidence notes
All statements above are grounded in the supplied NVD-derived record and its kernel stable patch references. The source corpus states the vulnerability was published on 2026-05-01 and last modified on 2026-05-17, describes the DACL validation gap in the Linux kernel SMB client, and lists affected Linux kernel versions from 5.12 through before 7.0.2. No exploit technique, proof of concept, or unsupported impact claims are included.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-31709 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-31709
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-31709 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-31709
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/0a8cf165566ba55a39fd0f4de172119dd646d39a
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/8e47d297e7cf9a6029a0d38e7b22faba7d7aaf12
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/b78db9bddc84136f6a0bb49e8883cf200dfb87a8
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d92f3f0b22414e7515696a02224d0af55e3004a3
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.