Red Hat and the Linux kernel CVE team disclosed CVE-2026-31709, an Important-severity flaw in the Linux kernel SMB client’s cifsacl code that can be triggered by a malicious SMB server. The bug stems from insufficient validation of a server-supplied DACL during chmod and chown security descriptor handling, allowing a truncated DACL with a valid header and overstated ACE count to drive out-of-bounds reads or copies in fs/smb/client/cifsacl.c. Red Hat assigned the issue a CVSS v3 score of 7.8 and said successful exploitation could cause memory corruption, information disclosure, or denial of service.
The vulnerable code was introduced in kernel 5.12, and the fix adds a shared validate_dacl() routine with full DACL and per-ACE bounds checks, which is also reused by parse_dacl() for consistent validation. Red Hat said corrected kernel packages have been released across multiple product streams including RHEL 8, RHEL 9, and RHEL 10, while RHEL 6 is not affected because the vulnerable code is absent; the issue is also included in RHSA-2026:23329 for RHEL 10. Red Hat advised customers to apply the updated kernel packages and reboot affected systems, and said organizations that do not need SMB client functionality can mitigate exposure by blacklisting the cifs kernel module.

See affected versions and whether adversaries are exploiting it.
10 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-04, Red Hat published RHSA-2026:23329, an Important kernel security advisory for RHEL 10 that included a fix for CVE-2026-31709. The advisory bundled seven kernel CVE fixes and instructed customers to reboot after applying the update.
On 2026-05-28, Red Hat released fixes for CVE-2026-31709 in RHEL 9 via RHSA-2026:21556 and in RHEL 8 via RHSA-2026:21706 and RHSA-2026:21745. These updates addressed the kernel SMB client cifsacl flaw across standard and kernel-rt package streams.
On 2026-05-01, the Linux kernel CVE team announced CVE-2026-31709 for insufficient validation of a server-supplied DACL in SMB client cifsacl. The advisory described how a malicious SMB server could trigger out-of-bounds reads or copies during chmod/chown security descriptor handling.
Red Hat's CVE page says its advisory for CVE-2026-31709 was last modified on 2026-06-30. The advisory documents the flaw as Important severity, provides mitigation guidance to blacklist the cifs module if unused, and lists affected and fixed product streams.
On 2026-06-08, Red Hat released RHSA-2026:24343 to address CVE-2026-31709 in Red Hat Enterprise Linux 10.0 Extended Update Support. This extended the fix to the RHEL 10 EUS stream.
On 2026-06-04, Red Hat also released fixes for CVE-2026-31709 in RHEL 9.4 Update Services for SAP Solutions via RHSA-2026:23237 and in RHEL 9.6 Extended Update Support via RHSA-2026:23224. These expanded patched coverage to additional supported RHEL 9 streams.
On 2026-06-03, Red Hat published fixes for CVE-2026-31709 for RHEL 9.2 Update Services for SAP Solutions through RHSA-2026:22900 and RHSA-2026:22940. The advisories covered both kernel and kernel-rt package variants.
The same vulnerability was also fixed in Linux kernel 7.1-rc1. The kernel CVE announcement identifies commit 0a8cf165566ba55a39fd0f4de172119dd646d39a as the corresponding fix.
The Linux kernel CVE announcement says CVE-2026-31709 was fixed in Linux kernel 7.0.2 by adding shared structural DACL validation with per-ACE bounds checks. It cites fixing commit b78db9bddc84136f6a0bb49e8883cf200dfb87a8.
The Linux kernel CVE announcement states the flawed SMB client cifsacl code path was introduced in Linux kernel 5.12. It attributes the introduction to commit bc3e9dd9d104ca1b75644eab87b38ce8a924aef4.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.