CVE-2026-31611
published 2026-04-24CVE-2026-31611: In the Linux kernel, the following vulnerability has been resolved: ksmbd: require 3 sub-authorities before reading sub_auth[2] parse_dacl() compares each ACE…
PriorityP345high8.6CVSS 3.1
AVNACLPRNUINSUCLILAH
EPSS
0.37%
28.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: require 3 sub-authorities before reading sub_auth[2]
parse_dacl() compares each ACE SID against sid_unix_NFS_mode and on
match reads sid.sub_auth[2] as the file mode. If sid_unix_NFS_mode is
the prefix S-1-5-88-3 with num_subauth = 2 then compare_sids() compares
only min(num_subauth, 2) sub-authorities so a client SID with
num_subauth = 2 and sub_auth = {88, 3} will match.
If num_subauth = 2 and the ACE is placed at the very end of the security
descriptor, sub_auth[2] will be 4 bytes past end_of_acl. The
out-of-band bytes will then be masked to the low 9 bits and applied as
the file's POSIX mode, probably not something that is good to have
happen.
Fix this up by forcing the SID to actually carry a third sub-authority
before reading it at all.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < cf2148b880fb7c0fcd727202dbc4fd5d6998b9c2 | cf2148b880fb7c0fcd727202dbc4fd5d6998b9c2 |
| linux | linux | >= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < b5b5d5936a50497fb151c0b122899a6894721c2b | b5b5d5936a50497fb151c0b122899a6894721c2b |
| linux | linux | >= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < 08f9e6d899b5c834bbcc239eae1bed58d9b15d2c | 08f9e6d899b5c834bbcc239eae1bed58d9b15d2c |
| linux | linux | >= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < d2454f4a002d08560a60f214f392e6491cf11560 | d2454f4a002d08560a60f214f392e6491cf11560 |
| linux | linux | >= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < 46bbcd3ebfb3549c8da1838fc4493e79bd3241e7 | 46bbcd3ebfb3549c8da1838fc4493e79bd3241e7 |
| linux | linux | >= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < 9401f86a224f37b50e6a3ccf1d46a70d5ef8af0a | 9401f86a224f37b50e6a3ccf1d46a70d5ef8af0a |
| linux | linux | >= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < 53370cf9090777774e07fd9a8ebce67c6cc333ab | 53370cf9090777774e07fd9a8ebce67c6cc333ab |
| linux | linux_kernel | >= 5.15 < 6.6.136 | 6.6.136 |
| linux | linux_kernel | >= 6.13 < 6.18.24 | 6.18.24 |
| linux | linux_kernel | >= 6.19 < 6.19.14 | 6.19.14 |
| linux | linux_kernel | >= 6.7 < 6.12.83 | 6.12.83 |
| linux | linux_kernel | >= 7.0 < 7.0.1 | 7.0.1 |
| ubuntu | linux | — | — |
| ubuntu | linux-aws | — | — |
| ubuntu | linux-gcp | — | — |
| ubuntu | linux-ibm | — | — |
| ubuntu | linux-nvidia | — | — |
| ubuntu | linux-oracle | — | — |
| ubuntu | linux-raspi | — | — |
| ubuntu | linux-realtime | — | — |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
vendor_ubuntu2.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (NVIDIA) vulnerabilities
vendor_ubuntu·2026-07-06·CVSS 2.0
CVE-2026-46009 [LOW] Linux kernel (NVIDIA) vulnerabilities
Title: Linux kernel (NVIDIA) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- x86 architecture;
- Block layer subsystem;
- Cryptographic API;
- Rados block device (RBD) driver;
- Compressed RAM block device driver;
- Character device driver;
- TPM device driver;
- Hardware crypto device drivers;
- EDAC drivers;
- GPU drivers;
- Greybus drive
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities
vendor_ubuntu·2026-07-02·CVSS 2.0
CVE-2026-46316 [LOW] Linux kernel (Raspberry Pi) vulnerabilities
Title: Linux kernel (Raspberry Pi) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- x86 architecture;
- Block layer subsystem;
- Cryptographic API;
- Rados block device (RBD) driver;
- Compressed RAM block device driver;
- Character device driver;
- TPM device driver;
- Hardware crypto device drivers;
- EDAC drivers;
- GPU drivers;
- Greybus
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2026-07-01·CVSS 2.0
CVE-2026-46042 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- x86 architecture;
- Block layer subsystem;
- Cryptographic API;
- Rados block device (RBD) driver;
- Compressed RAM block device driver;
- Character device driver;
- TPM device driver;
- Hardware crypto device drivers;
- EDAC drivers;
- GPU drivers;
- Greybus drivers;
- HID
Red Hat
kernel: ksmbd: require 3 sub-authorities before reading sub_auth[2]
vendor_redhat·2026-04-24
CVE-2026-31611 CWE-1285 kernel: ksmbd: require 3 sub-authorities before reading sub_auth[2]
kernel: ksmbd: require 3 sub-authorities before reading sub_auth[2]
A flaw was found in the ksmbd component of the Linux kernel. A remote attacker could exploit this vulnerability by sending a specially crafted Access Control Entry (ACE) that causes an out-of-bounds read when parsing security identifiers. This out-of-bounds read can lead to the application of arbitrary, unintended data as a file's POSIX mode, potentially resulting in incorrect file permissions and unauthorized access to files.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not
GHSA
GHSA-5q38-6rwh-6r7q: In the Linux kernel, the following vulnerability has been resolved:
ksmbd: require 3 sub-authorities before reading sub_auth[2]
parse_dacl() compare
ghsa_unreviewed·2026-04-24
CVE-2026-31611 GHSA-5q38-6rwh-6r7q: In the Linux kernel, the following vulnerability has been resolved:
ksmbd: require 3 sub-authorities before reading sub_auth[2]
parse_dacl() compare
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: require 3 sub-authorities before reading sub_auth[2]
parse_dacl() compares each ACE SID against sid_unix_NFS_mode and on
match reads sid.sub_auth[2] as the file mode. If sid_unix_NFS_mode is
the prefix S-1-5-88-3 with num_subauth = 2 then compare_sids() compares
only min(num_subauth, 2) sub-authorities so a client SID with
num_subauth = 2 and sub_auth = {88, 3} will match.
If num_subauth = 2 and the ACE is placed at the very end of the security
descriptor, sub_auth[2] will be 4 bytes past end_of_acl. The
out-of-band bytes will then be masked to the low 9 bits and applied as
the file's POSIX mode, probably not something that is good to have
happen.
Fix this up by forcing the SID to actually carry a third sub-auth
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/08f9e6d899b5c834bbcc239eae1bed58d9b15d2chttps://git.kernel.org/stable/c/46bbcd3ebfb3549c8da1838fc4493e79bd3241e7https://git.kernel.org/stable/c/53370cf9090777774e07fd9a8ebce67c6cc333abhttps://git.kernel.org/stable/c/9401f86a224f37b50e6a3ccf1d46a70d5ef8af0ahttps://git.kernel.org/stable/c/b5b5d5936a50497fb151c0b122899a6894721c2bhttps://git.kernel.org/stable/c/cf2148b880fb7c0fcd727202dbc4fd5d6998b9c2https://git.kernel.org/stable/c/d2454f4a002d08560a60f214f392e6491cf11560
2026-04-24
Published