CVE-2026-31613 is an out-of-bounds read vulnerability in the Linux kernel SMB client’s handling of symlink error responses. When an SMB CREATE response returns STATUS_STOPPED_ON_SYMLINK, smb2_check_message() accepts it without length validation. The symlink_data() parser subsequently traverses SMB 3.1.1 error contexts without ensuring that each complete context header fits and reads the matching symlink header without validating its extent. Server-controlled error-context lengths can therefore cause reads beyond the response buffer.
The smb2_parse_symlink_response() function also validates the substitute name using a fixed PathBuffer offset that is correct only when ErrorContextCount is zero. Error contexts move the actual symlink data deeper into the response, making this check insufficient. Heap bytes beyond the response buffer can be UTF-16-decoded into the symlink target and returned to userspace through readlink(2).
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
35 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed in a Red Hat Enterprise Linux 9.4 E4S kernel security update. The specific flaw and impact are not described.
Out-of-bounds reads in the Linux kernel SMB client when parsing a symlink error response. A fix is available through RHSA-2026:77218.
An out-of-bounds read vulnerability in the Linux kernel SMB client when parsing server-controlled symlink error responses. Incomplete error-context header validation and incorrect substitute-name bounds checks can cause reads beyond the response buffer, exposing heap contents through the symlink target returned by readlink(2). The reference rates the vulnerability High, with a CVSS v3 base score of 8.1.
An out-of-bounds read vulnerability in the Linux kernel SMB client when parsing symlink error responses.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.