PT-2026-36339 · Linux+3 · Linux Kernel+3

CVE-2026-31709

·

Published

2026-05-01

·

Updated

2026-08-30

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the SMB client where the system fails to fully validate the Discretionary Access Control List (DACL) before rewriting it in cifsacl. The functions build sec desc() and id mode to cifs acl() derive a DACL pointer from a server-supplied dacloffset to rebuild security descriptors for chmod/chown operations. While header fields are checked, the system does not perform structural validation of the DACL body. A malicious server can provide a truncated DACL that claims to contain one or more Access Control Entries (ACEs), causing replace sids and copy aces() or set chmod dacl() to read past the validated memory extent while processing attacker-controlled ACEs.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:21556
ALSA-2026:21706
ALSA-2026:21745
ALSA-2026:23329
AZL-85386
CVE-2026-31709
ECHO-9671-B50A-2F9F
OESA-2026-2675
OESA-2026-2676
OPENSUSE-SU-2026:10793-1
RHSA-2026:21556
RHSA-2026:21706
RHSA-2026:21745
RHSA-2026:22900
RHSA-2026:22940
RHSA-2026:23224
RHSA-2026:23237
RHSA-2026:23329
RHSA-2026:24343
USN-8488-1
USN-8488-2
USN-8507-1
USN-8567-1
USN-8569-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8603-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8619-1
USN-8665-1

Affected Products

Linuxmint
Linux Kernel
Rocky Linux
Ubuntu