CVE-2026-31613

HIGHPre-NVD 8.18.1
EchelonGraph scoreMEDIUM confidence

Score 8.1 from GitHub Security Advisory (severity: HIGH) published 2026-04-24. the CNA's CVSS baseline 8.1; sources differ by 0.0.

Triggered by: GitHub Security Advisory CVSS
Sources: cna:linux, epss, ghsa
8.1
EchelonGraph verdictPlan a fixSerious severity, but no confirmed exploitation yet.
  • High severity, but no confirmed exploitation yet
CISA-KEV: Not listedEPSS: 0%CVSS: 8.1Exploit: NoneExposed: 0

A fix is available — apply it.

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix OOB reads parsing symlink error response

When a CREATE returns STATUS_STOPPED_ON_SYMLINK, smb2_check_message() returns success without any length validation, leaving the symlink parsers as the only defense against an untrusted server.

symlink_data() walks SMB 3.1.1 error contexts with the loop test "p < end", but reads p->ErrorId at offset 4 and p->ErrorDataLength at offset

  • When the server-controlled ErrorDataLength advances p to within 1-7
bytes of end, the next iteration will read past it. When the matching context is found, sym->SymLinkErrorTag is read at offset 4 from p->ErrorContextData with no check that the symlink header itself fits.

smb2_parse_symlink_response() then bounds-checks the substitute name using SMB2_SYMLINK_STRUCT_SIZE as the offset of PathBuffer from iov_base. That value is computed as sizeof(smb2_err_rsp) + sizeof(smb2_symlink_err_rsp), which is correct only when ErrorContextCount == 0.

With at least one error context the symlink data sits 8 bytes deeper, and each skipped non-matching context shifts it further by 8 + ALIGN(ErrorDataLength, 8). The check is too short, allowing the substitute name read to run past iov_len. The out-of-bound heap bytes are UTF-16-decoded into the symlink target and returned to userspace via readlink(2).

Fix this all up by making the loops test require the full context header to fit, rejecting sym if its header runs past end, and bound the substitute name against the actual position of sym->PathBuffer rather than a fixed offset.

Because sub_offs and sub_len are 16bits, the pointer math will not overflow here with the new greater-than.

CVSS v3
8.1
EG Score
8.1(medium)
EPSS
30.3%
KEV
Not listed

Published

April 24, 2026

Last Modified

June 14, 2026

Advisory Details (4)

Auto-updated May 6, 2026
No patch confirmed yet.
generic

smb: client: fix OOB reads parsing symlink error response - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/e0dd90d14cbbf318157ea8e3fb62ee68a28655ed
generic

smb: client: fix OOB reads parsing symlink error response - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/a66ef2e7ed837325c5600f8617d5ee0a0a149fdd
generic

smb: client: fix OOB reads parsing symlink error response - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/781902e069f4ecb6c3b83502f181972c1446110a
generic

smb: client: fix OOB reads parsing symlink error response - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/3df690bba28edec865cf7190be10708ad0ddd67e

Patch Availability(5)

Vendor / EcosystemFixed in / PatchReleasedSource
redhatkernel-rt-0:4.18.0-553.132.1.rt7.473.el8_102026-06-10redhat
redhatkernel-0:4.18.0-553.132.1.el8_102026-06-10redhat
redhatkernel-0:5.14.0-687.13.1.el9_82026-06-08redhat
redhatkernel-0:6.12.0-211.20.1.el10_22026-06-04redhat
linuxKernel @ 6.1.175osv

Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.

Weakness Classification(1)

MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.

Data Freshness Timeline

(refreshed 14× in last 7d / 46× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

Showing the most recent 100 of 148 total refreshes for this CVE.

  1. 2026-07-22 14:08 UTCEPSS rescore
  2. 2026-07-22 14:08 UTCEPSS rescore
  3. 2026-07-21 15:24 UTCEPSS rescore
  4. 2026-07-21 15:24 UTCEPSS rescore
  5. 2026-07-20 17:08 UTCEPSS rescore
  6. 2026-07-20 17:08 UTCEPSS rescore
  7. 2026-07-20 16:34 UTCOSV refresh
  8. 2026-07-19 14:31 UTCEPSS rescore
  9. 2026-07-19 14:31 UTCEPSS rescore
  10. 2026-07-19 02:29 UTCEPSS rescore
  11. 2026-07-18 10:04 UTCEPSS rescore
  12. 2026-07-18 10:04 UTCEPSS rescore
  13. 2026-07-16 17:03 UTCEPSS rescore
  14. 2026-07-16 17:03 UTCEPSS rescore
  15. 2026-07-15 16:57 UTCEPSS rescore
  16. 2026-07-15 16:57 UTCEPSS rescore
  17. 2026-07-15 02:00 UTCEPSS rescore
  18. 2026-07-15 02:00 UTCEPSS rescore
  19. 2026-07-13 22:30 UTCEPSS rescore
  20. 2026-07-13 06:13 UTCEPSS rescore
  21. 2026-07-13 06:13 UTCEPSS rescore
  22. 2026-07-12 05:46 UTCEPSS rescore
  23. 2026-07-11 08:27 UTCEPSS rescore
  24. 2026-07-09 19:10 UTCEPSS rescore
  25. 2026-07-08 15:15 UTCEPSS rescore
Show 75 more
  1. 2026-07-07 13:46 UTCEPSS rescore
  2. 2026-07-06 16:27 UTCEPSS rescore
  3. 2026-07-06 16:27 UTCEPSS rescore
  4. 2026-07-06 02:23 UTCEPSS rescore
  5. 2026-07-06 02:23 UTCEPSS rescore
  6. 2026-07-05 02:30 UTCEPSS rescore
  7. 2026-07-04 06:31 UTCEPSS rescore
  8. 2026-07-01 15:06 UTCEPSS rescore
  9. 2026-06-30 23:22 UTCEPSS rescore
  10. 2026-06-29 14:06 UTCEPSS rescore
  11. 2026-06-29 14:06 UTCEPSS rescore
  12. 2026-06-28 14:07 UTCEPSS rescore
  13. 2026-06-28 14:07 UTCEPSS rescore
  14. 2026-06-28 04:56 UTCEPSS rescore
  15. 2026-06-28 04:56 UTCEPSS rescore
  16. 2026-06-27 03:08 UTCEPSS rescore
  17. 2026-06-25 13:49 UTCEPSS rescore
  18. 2026-06-25 13:49 UTCEPSS rescore
  19. 2026-06-24 14:05 UTCEPSS rescore
  20. 2026-06-23 21:33 UTCEPSS rescore
  21. 2026-06-23 21:33 UTCEPSS rescore
  22. 2026-06-22 14:25 UTCEPSS rescore
  23. 2026-06-22 14:25 UTCEPSS rescore
  24. 2026-06-21 14:56 UTCEPSS rescore
  25. 2026-06-21 14:56 UTCEPSS rescore
  26. 2026-06-21 01:59 UTCEPSS rescore
  27. 2026-06-19 19:25 UTCEPSS rescore
  28. 2026-06-19 19:25 UTCEPSS rescore
  29. 2026-06-18 17:52 UTCEPSS rescore
  30. 2026-06-18 17:52 UTCEPSS rescore
  31. 2026-06-17 17:53 UTCEPSS rescore
  32. 2026-06-16 17:52 UTCEPSS rescore
  33. 2026-06-15 17:49 UTCEPSS rescore
  34. 2026-06-15 02:08 UTCVendor advisory
  35. 2026-06-15 02:07 UTCGHSA enrichment
  36. 2026-06-14 23:18 UTCEPSS rescore
  37. 2026-06-14 11:53 UTCVendor advisory
  38. 2026-06-14 11:53 UTCGHSA enrichment
  39. 2026-06-13 23:00 UTCEPSS rescore
  40. 2026-06-12 23:12 UTCEPSS rescore
  41. 2026-06-12 23:12 UTCEPSS rescore
  42. 2026-06-12 02:27 UTCVendor advisory
  43. 2026-06-12 02:27 UTCGHSA enrichment
  44. 2026-06-11 14:02 UTCVendor advisory
  45. 2026-06-11 14:02 UTCGHSA enrichment
  46. 2026-06-11 14:00 UTCEPSS rescore
  47. 2026-06-10 22:18 UTCEPSS rescore
  48. 2026-06-10 14:06 UTCVendor advisory
  49. 2026-06-10 14:06 UTCGHSA enrichment
  50. 2026-06-10 13:22 UTCEPSS rescore
  51. 2026-06-10 01:39 UTCVendor advisory
  52. 2026-06-10 01:39 UTCGHSA enrichment
  53. 2026-06-09 13:13 UTCVendor advisory
  54. 2026-06-09 13:13 UTCGHSA enrichment
  55. 2026-06-09 00:48 UTCVendor advisory
  56. 2026-06-09 00:48 UTCGHSA enrichment
  57. 2026-06-08 14:17 UTCEPSS rescore
  58. 2026-06-08 14:17 UTCEPSS rescore
  59. 2026-06-08 08:53 UTCVendor advisory
  60. 2026-06-08 08:53 UTCGHSA enrichment
  61. 2026-06-07 20:28 UTCVendor advisory
  62. 2026-06-07 20:28 UTCGHSA enrichment
  63. 2026-06-07 15:25 UTCEPSS rescore
  64. 2026-06-07 15:25 UTCEPSS rescore
  65. 2026-06-07 15:25 UTCEPSS rescore
  66. 2026-06-07 08:02 UTCVendor advisory
  67. 2026-06-07 08:02 UTCGHSA enrichment
  68. 2026-06-06 19:37 UTCVendor advisory
  69. 2026-06-06 19:37 UTCGHSA enrichment
  70. 2026-06-06 13:47 UTCEPSS rescore
  71. 2026-06-06 13:47 UTCEPSS rescore
  72. 2026-06-06 06:39 UTCVendor advisory
  73. 2026-06-06 06:39 UTCGHSA enrichment
  74. 2026-06-05 22:47 UTCEPSS rescore
  75. 2026-06-05 22:47 UTCEPSS rescore

Frequently asked(5)

What is CVE-2026-31613?
CVE-2026-31613 is a high vulnerability published on April 24, 2026. In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOB reads parsing symlink error response When a CREATE returns STATUSSTOPPEDONSYMLINK, smb2check_message() returns success without any length validation, leaving the symlink parsers as the only defense against an…
When was CVE-2026-31613 disclosed?
CVE-2026-31613 was first published in the National Vulnerability Database on April 24, 2026, with the most recent update on June 14, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2026-31613 actively exploited?
CVE-2026-31613 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 30.3% percentile likelihood of exploitation in the next 30 days — higher percentiles indicate greater predicted risk.
What is the CVSS score of CVE-2026-31613?
CVE-2026-31613 has a CVSS v4.0 base score of 8.1 (CNA self-assessment; NVD's own analysis pending).
How do I remediate CVE-2026-31613?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2026-31613, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.

Dependency Blast Radius

Explore the affected products and dependency analysis for CVE-2026-31613

Explore →

Is Your Infrastructure Affected by CVE-2026-31613?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.