PT-2026-34383 · Linux · Linux Kernel

Published

2026-04-22

·

Updated

2026-04-27

·

CVE-2026-31478

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the ksmbd module where the smb2 calc max out buf len() function used a hardcoded magic number for the hdr2 len argument instead of the correct offset of the Buffer field in the response structure. This occurred after response buffer management was transitioned to use a dynamic iov array.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2026-31478
ECHO-FA0D-9DCB-C003

Affected Products

Linux Kernel