PT-2026-36347 · Linux+2 · Ksmbd+2

CVE-2026-31717

·

Published

2026-04-12

·

Updated

2026-08-30

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel ksmbd (affected versions not specified)
Description The ksmbd SMB server fails to verify if the user attempting to reconnect to a durable handle is the same user who originally opened the file. This allows an authenticated user to hijack an orphaned durable handle by predicting or brute-forcing the persistent ID. To address this, the server must ensure the SecurityContext of the reconnect request matches the SecurityContext associated with the existing open. The fix involves using a durable owner structure within ksmbd file to store the original opener's UID, GID, and account name, and implementing the ksmbd vfs compare durable owner() function to validate the requester's identity during SMB2 CREATE (DHnC).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12170
CVE-2026-31717
OESA-2026-2869
OESA-2026-3157
OPENSUSE-SU-2026:10793-1
USN-8488-1
USN-8488-2
USN-8507-1
USN-8569-1
USN-8603-1

Affected Products

Linuxmint
Ubuntu
Ksmbd