PT-2026-34890 · Linux · Linux Kernel

Published

2026-04-24

·

Updated

2026-04-29

·

CVE-2026-31538

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.18
Description A race condition exists in the SMB server logic used for managing receive credits. The process of counting posted recv io and granted credits is racy because a peer may consume a credit before the completion is processed in the recv done() function. This creates a window where credits are granted that do not actually exist.
Recommendations Update to version 6.18 or later.

Fix

Related Identifiers

CVE-2026-31538

Affected Products

Linux Kernel