CVE-2026-31476
published 2026-04-22CVE-2026-31476: In the Linux kernel, the following vulnerability has been resolved: ksmbd: do not expire session on binding failure When a multichannel session binding request…
PriorityP347high8.2CVSS 3.1
AVNACLPRNUINSUCNILAH
EPSS
0.50%
39.4th percentile
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: do not expire session on binding failure
When a multichannel session binding request fails (e.g. wrong password),
the error path unconditionally sets sess->state = SMB2_SESSION_EXPIRED.
However, during binding, sess points to the target session looked up via
ksmbd_session_lookup_slowpath() -- which belongs to another connection's
user. This allows a remote attacker to invalidate any active session by
simply sending a binding request with a wrong password (DoS).
Fix this by skipping session expiration when the failed request was
a binding attempt, since the session does not belong to the current
connection. The reference taken by ksmbd_session_lookup_slowpath() is
still correctly released via ksmbd_user_session_put().
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= f5a544e3bab78142207e0242d22442db85ba1eff < 4642ea35c03cf3d3558c009df4757cdb7af3f82d | 4642ea35c03cf3d3558c009df4757cdb7af3f82d |
| linux | linux | >= f5a544e3bab78142207e0242d22442db85ba1eff < f5300690c23c5ac860499bb37dbc09cf43fd62e6 | f5300690c23c5ac860499bb37dbc09cf43fd62e6 |
| linux | linux | >= f5a544e3bab78142207e0242d22442db85ba1eff < 6fafc4c4238e538969f1375f9ecdc6587c53f1cc | 6fafc4c4238e538969f1375f9ecdc6587c53f1cc |
| linux | linux | >= f5a544e3bab78142207e0242d22442db85ba1eff < 1d1888b4a7aec518b707f6eca0bf08992c0e8da3 | 1d1888b4a7aec518b707f6eca0bf08992c0e8da3 |
| linux | linux | >= f5a544e3bab78142207e0242d22442db85ba1eff < a897064a457056acb976e20e3007cdf553de340f | a897064a457056acb976e20e3007cdf553de340f |
| linux | linux | >= f5a544e3bab78142207e0242d22442db85ba1eff < e0e5edc81b241c70355217de7e120c97c3429deb | e0e5edc81b241c70355217de7e120c97c3429deb |
| linux | linux | >= f5a544e3bab78142207e0242d22442db85ba1eff < 9bbb19d21ded7d78645506f20d8c44895e3d0fb9 | 9bbb19d21ded7d78645506f20d8c44895e3d0fb9 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 5.15.1 < 6.1.168 | 6.1.168 |
| linux | linux_kernel | >= 6.13 < 6.18.21 | 6.18.21 |
| linux | linux_kernel | >= 6.19 < 6.19.11 | 6.19.11 |
| linux | linux_kernel | >= 6.2 < 6.6.131 | 6.6.131 |
| linux | linux_kernel | >= 6.7 < 6.12.80 | 6.12.80 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: ksmbd: do not expire session on binding failure
vendor_redhat·2026-04-22
CVE-2026-31476 CWE-274 kernel: ksmbd: do not expire session on binding failure
kernel: ksmbd: do not expire session on binding failure
A flaw was found in ksmbd in the Linux kernel. A remote attacker can exploit this vulnerability by sending a multichannel session binding request with an incorrect password. This improper handling of failed binding requests can cause an active session to expire, leading to a Denial of Service (DoS) for legitimate users.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Red Hat Enterprise Linux 9) -
VulDB
Linux Kernel up to 6.19.10 ksmbd ksmbd_session_lookup_slowpath denial of service (WID-SEC-2026-1252)
vuldb·2026-06-17·CVSS 8.2
CVE-2026-31476 [HIGH] Linux Kernel up to 6.19.10 ksmbd ksmbd_session_lookup_slowpath denial of service (WID-SEC-2026-1252)
A vulnerability labeled as critical has been found in Linux Kernel up to 6.1.167/6.6.130/6.12.79/6.18.20/6.19.10. Affected by this vulnerability is the function ksmbd_session_lookup_slowpath of the component ksmbd. Such manipulation leads to denial of service.
This vulnerability is documented as CVE-2026-31476. The attack requires being on the local network. There is not any exploit available.
The affected component should be upgraded.
GHSA
GHSA-223f-gch2-xvq3: In the Linux kernel, the following vulnerability has been resolved:
ksmbd: do not expire session on binding failure
When a multichannel session bind
ghsa_unreviewed·2026-04-22
CVE-2026-31476 GHSA-223f-gch2-xvq3: In the Linux kernel, the following vulnerability has been resolved:
ksmbd: do not expire session on binding failure
When a multichannel session bind
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: do not expire session on binding failure
When a multichannel session binding request fails (e.g. wrong password),
the error path unconditionally sets sess->state = SMB2_SESSION_EXPIRED.
However, during binding, sess points to the target session looked up via
ksmbd_session_lookup_slowpath() -- which belongs to another connection's
user. This allows a remote attacker to invalidate any active session by
simply sending a binding request with a wrong password (DoS).
Fix this by skipping session expiration when the failed request was
a binding attempt, since the session does not belong to the current
connection. The reference taken by ksmbd_session_lookup_slowpath() is
still correctly released via ksmbd_user_session_pu
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/1d1888b4a7aec518b707f6eca0bf08992c0e8da3https://git.kernel.org/stable/c/4642ea35c03cf3d3558c009df4757cdb7af3f82dhttps://git.kernel.org/stable/c/6fafc4c4238e538969f1375f9ecdc6587c53f1cchttps://git.kernel.org/stable/c/9bbb19d21ded7d78645506f20d8c44895e3d0fb9https://git.kernel.org/stable/c/a897064a457056acb976e20e3007cdf553de340fhttps://git.kernel.org/stable/c/e0e5edc81b241c70355217de7e120c97c3429debhttps://git.kernel.org/stable/c/f5300690c23c5ac860499bb37dbc09cf43fd62e6
2026-04-22
Published