CVE-2026-31392

Description

A flaw was found in the Linux kernel's Server Message Block (SMB) client. A local attacker, by attempting to mount SMB shares using Kerberos (sec=krb5) with a specified username, could cause the client to incorrectly reuse an existing SMB session. This session reuse occurs even when a different username is provided for subsequent mounts, potentially leading to an authentication bypass where shares are accessed with unintended credentials.

Statement

This is an authentication bypass vulnerability where SMB shares may be accessed with incorrect credentials due to improper session matching. A local user performing multiple Kerberos-authenticated SMB mounts with different usernames may inadvertently access shares using credentials from a previous mount. This could lead to unauthorized access to network resources.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score5.8N/A8.1
Attack VectorLocalN/ALocal
Attack ComplexityHighN/ALow
Privileges RequiredLowN/AHigh
User InteractionNoneN/ANone
ScopeUnchangedN/AChanged
ConfidentialityLowN/AHigh
Integrity ImpactLowN/AHigh
Availability ImpactHighN/ALow

Vector

Red Hat: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H

cve.org: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L

Understanding the Weakness (CWE)

Confidentiality

Technical Impact: Read Application Data

Frequently Asked Questions

Want to get errata notifications? Sign up here.