CVE-2026-31478

medium Red Hat
Published: April 22, 2026 (22 days ago)
Last Modified: April 22, 2026
Vendor: Red Hat
Source: REDHAT

Description

A flaw was found in ksmbd within the Linux kernel. This vulnerability occurs due to an incorrect calculation of the response buffer length in the `smb2_calc_max_out_buf_len()` function. The function used a hardcoded value instead of the proper offset, which could lead to issues in how response buffers are managed.

CWE

CWE-131

Affected Products

Red Hat Enterprise Linux 10Red Hat Enterprise Linux 6Red Hat Enterprise Linux 7Red Hat Enterprise Linux 8Red Hat Enterprise Linux 9

References