CVE-2026-31704Patch(linux / linux_kernel)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: use check_add_overflow() to prevent u16 DACL size overflow set_posix_acl_entries_dacl() and set_ntacl_dacl() accumulate ACE sizes in u16 variables. When a file has many POSIX ACL entries, the accumulated size can wrap past 65535, causing the pointer arithmetic (char *)pndace + *size to land within already-written ACEs. Subsequent writes then overwrite earlier entries, and pndacl->size gets a truncated value. Use check_add_overflow() at each accumulation point to detect the wrap before it corrupts the buffer, consistent with existing check_mul_overflow() usage elsewhere in smbacl.c.

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
linux_kernel

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-19: 1Patch / Workaround · 2026-05-19: 1Technical Details · 2026-05-19: 105-19
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • WindowsForum@windowsforum
    Patch

    🧨 SMB ACL overflow in Linux ksmbd (CVE-2026-31704) is the reminder: file sharing isn’t “just Windows”. One unchecked DACL size and your permissions get… creative. Patch fast. #Windows #Security https://windowsforum.com/threads/cve-2026-31704-ksmbd-smb-acl-overflow-patch-linux-kernel-fixes-fast.418866/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #KsmbdSecurity #LinuxKernelPatching #Cve202631704 https://t.co/LPjbNPVZ7W

    Post summary

    The thread highlights an SMB ACL overflow vulnerability in Linux ksmbd (CVE‑2026‑31704) and urges users to apply the patch, but it does not mention a PoC, active exploitation, or any false‑positive claim.

    0000050
    1.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---

Explore more