A path-traversal vulnerability in the Linux kernel ksmbd SMB server affects ksmbd_vfs_kern_path_create. Although SMB2 open lookup is constrained to the configured share with LOOKUP_BENEATH, the create, mkdir, and hardlink path-resolution flow constructed an absolute pathname and resolved it from the filesystem working-directory context. An authenticated SMB client can race a missing path component between the initial rooted lookup and the create-path walk. If the component is absent during lookup but becomes a directory during creation, a '..' component can be resolved outside the exported SMB share.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository `ksmbrace` contains two ksmbd vulnerability research subprojects. Structure is simple: top-level README plus two CVE directories, each with a write-up and runnable artifact. `CVE-2026-31717/` contains a Python PoC (`exploit.py`) and a Bash lab builder (`setup.sh`). The Python code uses Impacket SMB primitives and manually crafts SMB2 CREATE contexts for durable handle request/reconnect (`DHnQ`/`DHnC`) to hijack an orphaned durable handle by brute-forcing predictable persistent IDs. It supports three modes: `victim` (open and orphan handle), `attack` (scan a persistent-ID range and reconnect as another user), and `acl-bypass` (full end-to-end demonstration showing normal access denied before/after, but successful read/write through the hijacked handle). The setup script builds a vulnerable QEMU-based ksmbd environment, enables `durable handles = yes`, creates victim/attacker users, exports `/tmp/smbtest`, and forwards host TCP 44500 to guest 445. `CVE-2026-68083/` contains a README, a minimal C verifier (`poc/ksmbd_escape_min.c`), a Makefile, and a helper script (`scripts/run-escape-poc.sh`). This artifact is intentionally more defensive in scope: it is a raw SMB2 race-based verifier for a share-escape/path traversal bug in ksmbd's create path. The C code opens direct SMB2 sessions, sends literal traversal names that normal SMB clients would sanitize client-side, races a missing-component/open-lookup condition against directory creation, and then checks the local filesystem for escaped files in a chosen directory such as `/tmp`. Exit codes distinguish vulnerable, fixed, and cannot-test states. The helper script configures a temporary guest-enabled ksmbd share on loopback and runs the verifier locally. Overall purpose: the repository documents and demonstrates two authenticated ksmbd flaws. One is a true exploitation PoC enabling unauthorized file read/write across SMB users (CVE-2026-31717). The other is primarily a detection/verification tool for a race-based share escape (CVE-2026-68083), with explicit withholding of turnkey root-RCE chaining even though the README explains how such chaining could occur when shares map to uid 0.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.