CVE-2026-31536
published 2026-04-24CVE-2026-31536: In the Linux kernel, the following vulnerability has been resolved: smb: server: let send_done handle a completion without IB_SEND_SIGNALED With…
PriorityP349critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.44%
35.8th percentile
In the Linux kernel, the following vulnerability has been resolved:
smb: server: let send_done handle a completion without IB_SEND_SIGNALED
With smbdirect_send_batch processing we likely have requests without
IB_SEND_SIGNALED, which will be destroyed in the final request
that has IB_SEND_SIGNALED set.
If the connection is broken all requests are signaled
even without explicit IB_SEND_SIGNALED.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= 0626e6641f6b467447c81dd7678a69c66f7746cf < 24082642654f3e5149913946e89c00a297a8868f | 24082642654f3e5149913946e89c00a297a8868f |
| linux | linux | >= 0626e6641f6b467447c81dd7678a69c66f7746cf < e38b415c024bc3b6321bf8650dbf3f4aab8e74b3 | e38b415c024bc3b6321bf8650dbf3f4aab8e74b3 |
| linux | linux | >= 0626e6641f6b467447c81dd7678a69c66f7746cf < 9da82dc73cb03e85d716a2609364572367a5ff47 | 9da82dc73cb03e85d716a2609364572367a5ff47 |
| linux | linux_kernel | >= 5.15 < 6.18.11 | 6.18.11 |
| linux | linux_kernel | >= 6.19 < 6.19.1 | 6.19.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: smb: server: let send_done handle a completion without IB_SEND_SIGNALED
vendor_redhat·2026-04-24
CVE-2026-31536 CWE-166 kernel: smb: server: let send_done handle a completion without IB_SEND_SIGNALED
kernel: smb: server: let send_done handle a completion without IB_SEND_SIGNALED
A flaw was found in the Linux kernel's Server Message Block (SMB) direct server implementation. This issue occurs during `smbdirect_send_batch` processing where requests without the `IB_SEND_SIGNALED` flag may be incorrectly handled when a connection is broken. This could lead to unexpected behavior related to request completion and resource management within the SMB server.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Ent
GHSA
GHSA-pgx3-cx3f-6g2v: In the Linux kernel, the following vulnerability has been resolved:
smb: server: let send_done handle a completion without IB_SEND_SIGNALED
With smb
ghsa_unreviewed·2026-04-24
CVE-2026-31536 GHSA-pgx3-cx3f-6g2v: In the Linux kernel, the following vulnerability has been resolved:
smb: server: let send_done handle a completion without IB_SEND_SIGNALED
With smb
In the Linux kernel, the following vulnerability has been resolved:
smb: server: let send_done handle a completion without IB_SEND_SIGNALED
With smbdirect_send_batch processing we likely have requests without
IB_SEND_SIGNALED, which will be destroyed in the final request
that has IB_SEND_SIGNALED set.
If the connection is broken all requests are signaled
even without explicit IB_SEND_SIGNALED.
No detection rules found.
No public exploits indexed.
2026-04-24
Published