PT-2026-30175 · Linux · Linux Kernel

CVE-2026-31392

·

Published

2026-04-03

·

Updated

2026-07-24

CVSS v3.1

8.1

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel's SMB client related to Kerberos (krb5) mounting with the username option. The issue occurs when attempting to mount shares with different usernames using Kerberos authentication. The client incorrectly reuses an existing SMB session from a previous mount, even when a different username is specified, leading to authentication failures. Specifically, the client attempts to use credentials from the first mount for subsequent mounts, even if the username in the mount option has changed. This can result in errors like -ENOKEY when the specified principal is not found in the keytab file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-31392
ECHO-0EEA-3995-37E7
OESA-2026-2076
OESA-2026-2581
OPENSUSE-SU-2026:20826-1
SUSE-SU-2026:21834-1
SUSE-SU-2026:21841-1
SUSE-SU-2026:21845-1
SUSE-SU-2026:21860-1
SUSE-SU-2026:2217-1
SUSE-SU-2026:2238-1
USN-8567-1
USN-8574-1
USN-8574-2
USN-8595-1
USN-8595-2
USN-8596-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1

Affected Products

Linux Kernel