cbcvebase.
CVE-2026-31536
published 2026-04-24

CVE-2026-31536: In the Linux kernel, the following vulnerability has been resolved: smb: server: let send_done handle a completion without IB_SEND_SIGNALED With…

PriorityP349critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.44%
35.8th percentile
In the Linux kernel, the following vulnerability has been resolved: smb: server: let send_done handle a completion without IB_SEND_SIGNALED With smbdirect_send_batch processing we likely have requests without IB_SEND_SIGNALED, which will be destroyed in the final request that has IB_SEND_SIGNALED set. If the connection is broken all requests are signaled even without explicit IB_SEND_SIGNALED.

Affected

6 ranges
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 24082642654f3e5149913946e89c00a297a8868f24082642654f3e5149913946e89c00a297a8868f
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < e38b415c024bc3b6321bf8650dbf3f4aab8e74b3e38b415c024bc3b6321bf8650dbf3f4aab8e74b3
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 9da82dc73cb03e85d716a2609364572367a5ff479da82dc73cb03e85d716a2609364572367a5ff47
linuxlinux_kernel>= 5.15 < 6.18.116.18.11
linuxlinux_kernel>= 6.19 < 6.19.16.19.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.