CVE-2026-31710
Linux Ubuntu vulnerability analysis and mitigation

Overview

CVE-2026-31710 is a vulnerability in the Linux kernel's SMB client code affecting directory path separator handling for SMB1 UNIX mounts. When cifs_mount_get_tcon() is called, cifs_sb->mnt_cifs_flags is read or updated before reset_cifs_unix_caps() is called, resulting in missing CIFS_MOUNT_POSIXACL and CIFS_MOUNT_POSIX_PATHS bits and causing incorrect directory separators in path operations. The vulnerability affects Linux kernel versions 7.0 through 7.0.1 (fixed in 7.0.2) and was published on May 1, 2026. It carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory / Path Traversal), arising from a race condition in flag initialization order within the CIFS/SMB client subsystem. Specifically, in cifs_mount_get_tcon(), the mnt_cifs_flags field of cifs_sb_info is accessed before reset_cifs_unix_caps() has had the opportunity to set the CIFS_MOUNT_POSIX_PATHS and CIFS_MOUNT_POSIXACL bits, leading to path corruption where backslash separators are used instead of forward slashes. Exploitation requires local access and the ability to mount SMB1 UNIX shares. Upstream fix commits are c4d3fc5844d685441befd0caaab648321013cdfd and fbbfcf35e1ee3396631f3dc6214cb626aa9814c3 (Red Hat Bugzilla, Kernel Commit 1, Kernel Commit 2).

Impact

Successful exploitation by a local user with SMB1 UNIX mount access causes file operations to use incorrect path separators, resulting in path corruption, file access failures, and service unavailability on mounted SMB shares. The primary impact is availability (denial of service), with no direct confidentiality or integrity compromise. The vulnerability is scoped to the local system and does not provide a pathway for privilege escalation or lateral movement (Red Hat Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.018% (0.000180), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local access and the use of SMB1 UNIX mounts, significantly limiting the attack surface (Red Hat Advisory).

Mitigation and workarounds

Update the Linux kernel to version 7.0.2 or later, which includes the upstream fix commits c4d3fc5844d685441befd0caaab648321013cdfd and fbbfcf35e1ee3396631f3dc6214cb626aa9814c3. As an interim workaround, avoid using SMB1 UNIX mounts and migrate to SMB2 or SMB3 where possible, as these protocol versions are not affected. OpenSUSE has also issued a security announcement for this vulnerability (Red Hat Advisory, Kernel Commit 1, OpenSUSE Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

linux

Fixed

sid

linux

Fixed

trixie

linux

Fixed

Ubuntu

Fixed

bionic

linux

Not Affected

bionic (esm-infra)

linux

Not Affected

bionic (fips-updates)

linux-fips

Not Affected

bionic (fips)

linux-fips

Not Affected

devel

linux-azure-fde

Affected

focal

linux

Not Affected

focal (esm-infra)

linux

Not Affected

focal (fips-updates)

linux-fips

Not Affected

RHEL / CentOS

Affected

RHEL 8

Not Affected

RHEL 9

Not Affected

RHEL 10

Not Affected

SourceThis report was generated using AI

Related Linux Ubuntu vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-54241HIGH7.4
  • Linux Debian logoLinux Debian
  • libde265
NoYesSep 11, 2026
CVE-2026-54240HIGH7.4
  • Linux Debian logoLinux Debian
  • libde265-debugsource
NoYesSep 11, 2026
CVE-2026-19816HIGH7.1
  • Linux Debian logoLinux Debian
  • PackageKit-glib
NoNoSep 11, 2026
CVE-2026-49838MEDIUM5.9
  • Wolfi logoWolfi
  • cilium-cli
NoYesSep 10, 2026
CVE-2026-49837MEDIUM5.9
  • Linux Debian logoLinux Debian
  • gobgp
NoYesSep 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management