cbcvebase.
CVE-2026-31611
published 2026-04-24

CVE-2026-31611: In the Linux kernel, the following vulnerability has been resolved: ksmbd: require 3 sub-authorities before reading sub_auth[2] parse_dacl() compares each ACE…

PriorityP345high8.6CVSS 3.1
AVNACLPRNUINSUCLILAH
EPSS
0.37%
28.9th percentile
In the Linux kernel, the following vulnerability has been resolved: ksmbd: require 3 sub-authorities before reading sub_auth[2] parse_dacl() compares each ACE SID against sid_unix_NFS_mode and on match reads sid.sub_auth[2] as the file mode. If sid_unix_NFS_mode is the prefix S-1-5-88-3 with num_subauth = 2 then compare_sids() compares only min(num_subauth, 2) sub-authorities so a client SID with num_subauth = 2 and sub_auth = {88, 3} will match. If num_subauth = 2 and the ACE is placed at the very end of the security descriptor, sub_auth[2] will be 4 bytes past end_of_acl. The out-of-band bytes will then be masked to the low 9 bits and applied as the file's POSIX mode, probably not something that is good to have happen. Fix this up by forcing the SID to actually carry a third sub-authority before reading it at all.

Affected

21 ranges
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < cf2148b880fb7c0fcd727202dbc4fd5d6998b9c2cf2148b880fb7c0fcd727202dbc4fd5d6998b9c2
linuxlinux>= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < b5b5d5936a50497fb151c0b122899a6894721c2bb5b5d5936a50497fb151c0b122899a6894721c2b
linuxlinux>= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < 08f9e6d899b5c834bbcc239eae1bed58d9b15d2c08f9e6d899b5c834bbcc239eae1bed58d9b15d2c
linuxlinux>= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < d2454f4a002d08560a60f214f392e6491cf11560d2454f4a002d08560a60f214f392e6491cf11560
linuxlinux>= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < 46bbcd3ebfb3549c8da1838fc4493e79bd3241e746bbcd3ebfb3549c8da1838fc4493e79bd3241e7
linuxlinux>= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < 9401f86a224f37b50e6a3ccf1d46a70d5ef8af0a9401f86a224f37b50e6a3ccf1d46a70d5ef8af0a
linuxlinux>= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < 53370cf9090777774e07fd9a8ebce67c6cc333ab53370cf9090777774e07fd9a8ebce67c6cc333ab
linuxlinux_kernel>= 5.15 < 6.6.1366.6.136
linuxlinux_kernel>= 6.13 < 6.18.246.18.24
linuxlinux_kernel>= 6.19 < 6.19.146.19.14
linuxlinux_kernel>= 6.7 < 6.12.836.12.83
linuxlinux_kernel>= 7.0 < 7.0.17.0.1
ubuntulinux
ubuntulinux-aws
ubuntulinux-gcp
ubuntulinux-ibm
ubuntulinux-nvidia
ubuntulinux-oracle
ubuntulinux-raspi
ubuntulinux-realtime

CVSS provenance

nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
vendor_ubuntu2.0LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.