PT-2026-30175 · Linux · Linux Kernel
Published
2026-04-03
·
Updated
2026-04-25
·
CVE-2026-31392
CVSS v3.1
8.1
High
| Vector | AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A flaw exists in the Linux kernel's SMB client related to Kerberos (krb5) mounting with the username option. The issue occurs when attempting to mount shares with different usernames using Kerberos authentication. The client incorrectly reuses an existing SMB session from a previous mount, even when a different username is specified, leading to authentication failures. Specifically, the client attempts to use credentials from the first mount for subsequent mounts, even if the username in the mount option has changed. This can result in errors like -ENOKEY when the specified principal is not found in the keytab file.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel