PT-2026-34963 · Linux+2 · Linux Kernel+2

CVE-2026-31611

·

Published

2026-04-12

·

Updated

2026-08-25

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description In the ksmbd module, the parse dacl() function compares each Access Control Entry (ACE) Security Identifier (SID) against sid unix NFS mode. If sid unix NFS mode is the prefix S-1-5-88-3 with num subauth equal to 2, a client SID with num subauth equal to 2 and sub auth equal to {88, 3} will match. If the ACE is located at the end of the security descriptor, the system reads sub auth[2], which is 4 bytes beyond the end of the Access Control List (ACL). These out-of-band bytes are then masked to the low 9 bits and applied as the file's POSIX mode.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-83753
BDU:2026-12585
CVE-2026-31611
ECHO-A4CC-4540-6BD4
OESA-2026-2416
OPENSUSE-SU-2026:10703-1
USN-8488-1
USN-8488-2
USN-8507-1
USN-8567-1
USN-8569-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8603-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8619-1
USN-8665-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu