OVERVIEW CVE-2026-31477 is a vulnerability in the Linux kernel's SMB2 locking mechanism (smb2_lock function) affecting the ksmbd subsystem. The vulnerability encompasses multiple error handling flaws that lead to memory leaks and potential NULL pointer dereference conditions when processing lock and unlock requests. SEVERITY The vulnerability carries a CVSS score that is currently unavailable, though the EPSS score of 0.00024 indicates minimal statistical likelihood of exploitation compared to other CVEs. The attack vector requires local access to the affected system, and exploitation would demand moderate complexity. The potential impact includes denial of service through kernel crashes via NULL pointer dereference and memory exhaustion through repeated leak conditions, though no direct remote exploitation path exists. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, as this vulnerability does not appear on the CISA Known Exploited Vulnerabilities catalog. The vulnerability was identified through automated static analysis (sqry call-graph analysis) rather than in-the-wild exploitation reports. No public exploit code is currently available, and community attention remains minimal given the specialized nature of the ksmbd subsystem and the low EPSS score. The fix has been integrated into the Linux kernel development process through proper patch submission channels.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.15.1, < 6.1.168CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.6.131CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.7, < 6.12.80CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.13, < 6.18.21CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.19, < 6.19.11CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel (Azure CVM) vulnerabilities
Jul 24, 2026Linux kernel (Azure FIPS) vulnerabilities
Jul 24, 2026Linux kernel (Azure CVM) vulnerabilities
Jul 24, 2026Linux kernel (Azure) vulnerabilities
Jul 24, 2026Linux kernel (AWS) vulnerabilities
Jul 24, 2026Linux kernel (NVIDIA) vulnerabilities
Jul 23, 2026Linux kernel (Oracle) vulnerabilities
Jul 23, 2026Linux kernel vulnerabilities
Jul 23, 2026Linux kernel (GCP FIPS) vulnerabilities
Jul 21, 2026Linux kernel vulnerabilities
Jul 20, 2026ksmbd: fix memory leaks and NULL deref in smb2_lock()
Apr 14, 2026