Out-of-bounds write in Linux kernel - CVE-2026-31433
Published: April 24, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to out-of-bounds write in get_file_all_info() when processing a compound QUERY_DIRECTORY + QUERY_INFO (FILE_ALL_INFORMATION) request. A remote user can send a specially crafted compound request to cause a denial of service.
The issue is triggered when the first command in the compound request consumes nearly the entire maximum transaction size.
How to mitigate CVE-2026-31433
Sources
- https://git.kernel.org/stable/c/358cdaa1f7fbf2712cb4c5f6b59cb9a5c673c5fe
- https://git.kernel.org/stable/c/3a852f9d1c981fb14f6bf4e24999e0ea8088a7d7
- https://git.kernel.org/stable/c/4cca3eff2099b18672934a39cee70aed835d652c
- https://git.kernel.org/stable/c/7aec5a769d2356cbf344d85bcfd36de592ac96a5
- https://git.kernel.org/stable/c/9d7032851d6f5adbe2739601ca456c0ad3b422f0
- https://git.kernel.org/stable/c/b0cd9725fe2bcc9f37d096b132318a9060373f5d
- https://git.kernel.org/stable/c/beef2634f81f1c086208191f7228bce1d366493d