CVE-2026-31612

Description

A flaw was found in ksmbd, a Linux kernel module. A remote attacker can exploit this vulnerability by sending a specially crafted client request to the smb2_get_ea() function. Due to improper validation of the EaNameLength field, the system may leak uninitialized heap memory values, leading to information disclosure.

Understanding the Weakness (CWE)

Confidentiality,Integrity

Technical Impact: Read Memory; Modify Memory; Varies by Context

Frequently Asked Questions

Want to get errata notifications? Sign up here.