CVE Database
/

CVE-2026-31536

Back to search

CVE-2026-31536

Published: Apr 24, 2026

Modified: May 11, 2026

PUBLISHED

CVSS v3.1

9.8

CRITICAL

Description

In the Linux kernel, the following vulnerability has been resolved: smb: server: let send_done handle a completion without IB_SEND_SIGNALED With smbdirect_send_batch processing we likely have requests without IB_SEND_SIGNALED, which will be destroyed in the final request that has IB_SEND_SIGNALED set. If the connection is broken all requests are signaled even without explicit IB_SEND_SIGNALED.

VendorProductVersions

Linux

Linux

affected
0626e6641f6b467447c81dd7678a69c66f7746cf - < 24082642654f3e5149913946e89c00a297a8868f
affected
0626e6641f6b467447c81dd7678a69c66f7746cf - < e38b415c024bc3b6321bf8650dbf3f4aab8e74b3
affected
0626e6641f6b467447c81dd7678a69c66f7746cf - < 9da82dc73cb03e85d716a2609364572367a5ff47

Linux

Linux

affected
5.15
unaffected
0 - < 5.15
unaffected
6.18.11 - <= 6.18.*
unaffected
6.19.1 - <= 6.19.*
unaffected
7.0 - <= *

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now