PT-2026-34965 · Linux+3 · Linux Kernel+3

CVE-2026-31613

·

Published

2026-04-07

·

Updated

2026-08-30

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the SMB client when parsing symlink error responses. When a CREATE request returns STATUS STOPPED ON SYMLINK, the smb2 check message() function returns success without length validation. The symlink data() function may read past the end of the buffer when processing SMB 3.1.1 error contexts if the server-controlled ErrorDataLength advances the pointer too close to the end. Additionally, smb2 parse symlink response() uses a fixed offset for the substitute name check, which is only accurate when ErrorContextCount is zero. If error contexts are present, the substitute name read can exceed the buffer length, causing out-of-bound heap bytes to be UTF-16-decoded and returned to userspace via readlink(2).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:23329
ALSA-2026:24381
ALSA-2026:25120
ALSA-2026:25121
AZL-83774
BDU:2026-12586
CVE-2026-31613
ECHO-7815-EA2E-7BED
OPENSUSE-SU-2026:10703-1
OPENSUSE-SU-2026:20912-1
RHSA-2026:23329
RHSA-2026:24381
RHSA-2026:25120
RHSA-2026:25121
RHSA-2026:40068
RHSA-2026:40760
SUSE-SU-2026:22043-1
SUSE-SU-2026:22048-1
SUSE-SU-2026:22076-1
SUSE-SU-2026:22087-1
SUSE-SU-2026:22108-1
SUSE-SU-2026:22137-1
SUSE-SU-2026:22433-1
SUSE-SU-2026:22458-1
SUSE-SU-2026:2310-1
SUSE-SU-2026:2482-1
SUSE-SU-2026:2591-1
SUSE-SU-2026:2630-1
SUSE-SU-2026:2631-1
SUSE-SU-2026:2638-1
SUSE-SU-2026:2658-1
USN-8488-1
USN-8488-2
USN-8507-1
USN-8567-1
USN-8569-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8603-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8619-1
USN-8665-1

Affected Products

Linuxmint
Linux Kernel
Rocky Linux
Ubuntu