cbcvebase.
CVE-2026-31693
published 2026-04-30

CVE-2026-31693: In the Linux kernel, the following vulnerability has been resolved: cifs: some missing initializations on replay In several places in the code, we have a label…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
2.9th percentile
In the Linux kernel, the following vulnerability has been resolved: cifs: some missing initializations on replay In several places in the code, we have a label to signify the start of the code where a request can be replayed if necessary. However, some of these places were missing the necessary reinitializations of certain local variables before replay. This change makes sure that these variables get initialized after the label.

Affected

39 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 433042a91f9373241307725b52de573933ffedbf < c854ab481ece4b3e5f4c2e8b22824f015ff874a5c854ab481ece4b3e5f4c2e8b22824f015ff874a5
linuxlinux>= 4f1fffa2376922f3d1d506e49c0fd445b023a28e < 1d731e512134495e0ef490ade0e4d91dc0d515ec1d731e512134495e0ef490ade0e4d91dc0d515ec
linuxlinux>= 4f1fffa2376922f3d1d506e49c0fd445b023a28e < 7c9ce68192eef14c777cb6ce17155d2eb2431aea7c9ce68192eef14c777cb6ce17155d2eb2431aea
linuxlinux>= 4f1fffa2376922f3d1d506e49c0fd445b023a28e < c99e160938b627f6f28edee930e8abc157e84386c99e160938b627f6f28edee930e8abc157e84386
linuxlinux>= 4f1fffa2376922f3d1d506e49c0fd445b023a28e < 14f66f44646333d2bfd7ece36585874fd72f828614f66f44646333d2bfd7ece36585874fd72f8286
linuxlinux>= 6.6.32 < 6.6.1286.6.128
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 6.13 < 6.18.166.18.16
linuxlinux_kernel>= 6.19 < 6.19.66.19.6
linuxlinux_kernel>= 6.6.32 < 6.6.1286.6.128
linuxlinux_kernel>= 6.8.1 < 6.12.756.12.75
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-aws-fips
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp
ubuntulinux-gcp-6.8
ubuntulinux-gcp-fips
ubuntulinux-gke
ubuntulinux-gkeop
ubuntulinux-ibm

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu8.8HIGH
vendor_redhat7.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.