PT-2026-34890 · Linux · Linux Kernel
CVE-2026-31538
·
Published
2026-04-24
·
Updated
2026-05-03
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.18
Description
A race condition exists in the SMB server logic used for managing receive credits. The process of counting posted
recv io and granted credits is racy because a peer may consume a credit before the completion is processed in the recv done() function. This creates a window where credits are granted that do not actually exist.Recommendations
Update to version 6.18 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel