PT-2026-34890 · Linux · Linux Kernel

CVE-2026-31538

·

Published

2026-04-24

·

Updated

2026-05-03

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.18
Description A race condition exists in the SMB server logic used for managing receive credits. The process of counting posted recv io and granted credits is racy because a peer may consume a credit before the completion is processed in the recv done() function. This creates a window where credits are granted that do not actually exist.
Recommendations Update to version 6.18 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-31538

Affected Products

Linux Kernel