Answer in brief
CVE-2026-31708 records a High severity (CVSS 8.1) vulnerability in smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-31708 records a High severity (CVSS 8.1) vulnerability in smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.1. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f5778c398713692a16150ae96e5c8270bab8399f <e66bdc0704977ecee667a81d38255b579c2353d0 || >=f5778c398713692a16150ae96e5c8270bab8399f <9e203dbb5402897c43130fb171a2617008a91f45 || >=f5778c398713692a16150ae96e5c8270bab8399f <1dd757379997b71a328a4b591ffaf481acd0ead1 || >=f5778c398713692a16150ae96e5c8270bab8399f <a34d456934fe42e4da5d2cc07787bf418bee99c6 || >=f5778c398713692a16150ae96e5c8270bab8399f <ac2f14e4705d020f04e806efa0d49ab8dc2b145f || >=f5778c398713692a16150ae96e5c8270bab8399f <078fae8f50adebb903ccf2252b44391324571e78 || >=f5778c398713692a16150ae96e5c8270bab8399f <85fd46ee26a11841c670449508025965f61ce131 || >=f5778c398713692a16150ae96e5c8270bab8399f <a58c5af19ff0d6f44f6e9fe31e33a2c92223f77e | e66bdc0704977ecee667a81d38255b579c2353d0, 9e203dbb5402897c43130fb171a2617008a91f45, 1dd757379997b71a328a4b591ffaf481acd0ead1, a34d456934fe42e4da5d2cc07787bf418bee99c6, ac2f14e4705d020f04e806efa0d49ab8dc2b145f, 078fae8f50adebb903ccf2252b44391324571e78, 85fd46ee26a11841c670449508025965f61ce131, a58c5af19ff0d6f44f6e9fe31e33a2c92223f77e |
| Linux/Linuxgeneric | 5.1 | Not reported |
Published upstream
May 1, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jun 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jun 19, 2026
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path smb2_ioctl_query_info() has two response-copy branches: PASSTHRU_FSCTL and the default QUERY_INFO path. The QUERY_INFO branch clamps qi.input_buffer_length to the server-reported OutputBufferLength and then copies qi.input_buffer_length bytes from qi_rsp->Buffer to userspace, but it never verifies that the flexible-array payload actually fits within rsp_iov[1].iov_len. A malicious server can return OutputBufferLength larger than the actual QUERY_INFO response, causing copy_to_user() to walk past the response buffer and expose adjacent kernel heap to userspace. Guard the QUERY_INFO copy with a bounds check on the actual Buffer payload. Use struct_size(qi_rsp, Buffer, qi.input_buffer_length) rather than an open-coded addition so the guard cannot overflow on 32-bit builds.
Quoted source text, attributed separately from HOL analysis.
CVSS is 8.1. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f5778c398713692a16150ae96e5c8270bab8399f <e66bdc0704977ecee667a81d38255b579c2353d0 || >=f5778c398713692a16150ae96e5c8270bab8399f <9e203dbb5402897c43130fb171a2617008a91f45 || >=f5778c398713692a16150ae96e5c8270bab8399f <1dd757379997b71a328a4b591ffaf481acd0ead1 || >=f5778c398713692a16150ae96e5c8270bab8399f <a34d456934fe42e4da5d2cc07787bf418bee99c6 || >=f5778c398713692a16150ae96e5c8270bab8399f <ac2f14e4705d020f04e806efa0d49ab8dc2b145f || >=f5778c398713692a16150ae96e5c8270bab8399f <078fae8f50adebb903ccf2252b44391324571e78 || >=f5778c398713692a16150ae96e5c8270bab8399f <85fd46ee26a11841c670449508025965f61ce131 || >=f5778c398713692a16150ae96e5c8270bab8399f <a58c5af19ff0d6f44f6e9fe31e33a2c92223f77e | e66bdc0704977ecee667a81d38255b579c2353d0, 9e203dbb5402897c43130fb171a2617008a91f45, 1dd757379997b71a328a4b591ffaf481acd0ead1, a34d456934fe42e4da5d2cc07787bf418bee99c6, ac2f14e4705d020f04e806efa0d49ab8dc2b145f, 078fae8f50adebb903ccf2252b44391324571e78, 85fd46ee26a11841c670449508025965f61ce131, a58c5af19ff0d6f44f6e9fe31e33a2c92223f77e |
| Linux/Linuxgeneric | 5.1 | Not reported |
Published upstream
May 1, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jun 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jun 19, 2026
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path smb2_ioctl_query_info() has two response-copy branches: PASSTHRU_FSCTL and the default QUERY_INFO path. The QUERY_INFO branch clamps qi.input_buffer_length to the server-reported OutputBufferLength and then copies qi.input_buffer_length bytes from qi_rsp->Buffer to userspace, but it never verifies that the flexible-array payload actually fits within rsp_iov[1].iov_len. A malicious server can return OutputBufferLength larger than the actual QUERY_INFO response, causing copy_to_user() to walk past the response buffer and expose adjacent kernel heap to userspace. Guard the QUERY_INFO copy with a bounds check on the actual Buffer payload. Use struct_size(qi_rsp, Buffer, qi.input_buffer_length) rather than an open-coded addition so the guard cannot overflow on 32-bit builds.
Quoted source text, attributed separately from HOL analysis.