PT-2026-30175 · Linux · Linux Kernel

Published

2026-04-03

·

Updated

2026-04-25

·

CVE-2026-31392

CVSS v3.1

8.1

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel's SMB client related to Kerberos (krb5) mounting with the username option. The issue occurs when attempting to mount shares with different usernames using Kerberos authentication. The client incorrectly reuses an existing SMB session from a previous mount, even when a different username is specified, leading to authentication failures. Specifically, the client attempts to use credentials from the first mount for subsequent mounts, even if the username in the mount option has changed. This can result in errors like -ENOKEY when the specified principal is not found in the keytab file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2026-31392
ECHO-0EEA-3995-37E7
OESA-2026-2076

Affected Products

Linux Kernel