Red Hat disclosed two Important Linux kernel vulnerabilities in the SMB client’s cifsacl handling that can be triggered by a malicious SMB server and lead to memory corruption. CVE-2026-31709 affects DACL parsing when a server advertises more ACEs than are actually present, causing insufficient validation and resulting in out-of-bounds memory read or copy behavior. Red Hat said the flaw can cause information disclosure or denial of service and assigned it a CVSS v3 score of 7.8.
A second flaw, CVE-2026-46195, affects 32-bit Red Hat Enterprise Linux systems and stems from a crafted dacloffset value that can trigger pointer wrap during chmod or chown operations, leading to invalid DACL dereferences and memory corruption. Red Hat warned the issue could cause denial of service or bypass security mechanisms, scored it 7.5, and mapped it to CWE-787, a class of out-of-bounds write weaknesses that can corrupt memory and potentially alter program control flow. Red Hat published fixes across multiple RHEL 8 and 9 kernel streams, noted some product variants remained affected at disclosure, and advised organizations that do not need SMB client functionality to blacklist the cifs kernel module as a mitigation.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat released further CVE-2026-31709 fixes for RHEL 10 kernel, RHEL 9.4 Update Services for SAP Solutions kernel, and RHEL 9.6 Extended Update Support kernel in advisories RHSA-2026:23329, RHSA-2026:23237, and RHSA-2026:23224. These advisories expanded fixed coverage across additional enterprise product streams.
Additional fixes for CVE-2026-31709 were released for RHEL 9.2 Update Services for SAP Solutions kernel and kernel-rt packages in advisories RHSA-2026:22940 and RHSA-2026:22900. These updates extended remediation coverage to SAP-focused RHEL 9.2 streams.
Red Hat listed fixed packages for CVE-2026-31709 in RHEL 8 kernel-rt, RHEL 8 kernel, and RHEL 9 kernel through advisories RHSA-2026:21745, RHSA-2026:21706, and RHSA-2026:21556. These updates addressed the SMB client cifsacl validation flaw in affected product streams.
On the same day as disclosure, Red Hat listed fixes for CVE-2026-46195 in RHEL 8 kernel-rt, RHEL 8 kernel, and RHEL 9 kernel advisories RHSA-2026:21745, RHSA-2026:21706, and RHSA-2026:21556. RHEL 10 kernel and RHEL 9 kernel-rt remained affected at the time of the notice.
Red Hat disclosed CVE-2026-46195, an Important-severity Linux kernel SMB client vulnerability affecting 32-bit Red Hat Enterprise Linux systems, where a crafted dacloffset from a malicious SMB server can trigger pointer wrap and memory corruption during chmod or chown operations. The notice included mitigation guidance to avoid mounts from untrusted SMB servers and mapped the issue to CWE-787.
Red Hat published an advisory for CVE-2026-31709, an Important-severity Linux kernel SMB client cifsacl flaw in which a malformed DACL can advertise more ACEs than are present, causing out-of-bounds memory read or copy behavior and possible memory corruption. Red Hat classified the issue as CWE-1288 and recommended blacklisting the cifs kernel module if SMB client functionality is not needed.
Red Hat published RHSA-2026:24343 to fix CVE-2026-31709 in RHEL 10.0 Extended Update Support kernel packages. This completed another product-stream-specific remediation step for the SMB client flaw.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.