Out-of-bounds read in Linux kernel - CVE-2026-31614
Published: April 25, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in check_wsl_eas() when processing extended attribute data from an SMB server response. A remote attacker can send a specially crafted server response to disclose sensitive information.
The issue can leak up to 8 bytes of kernel heap memory and can influence which WSL xattr the data is interpreted as.