# CVE-2026-31432

> Vulnerability · severity: **HIGH** (CVSS 8.8).

## Description

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix OOB write in QUERY_INFO for compound requests

When a compound request such as READ + QUERY_INFO(Security) is received,
and the first command (READ) consumes most of the response buffer,
ksmbd could write beyond the allocated buffer while building a security
descriptor.

The root cause was that smb2_get_info_sec() checked buffer space using
ppntsd_size from xattr, while build_sec_desc() often synthesized a
significantly larger descriptor from POSIX ACLs.

This patch introduces smb_acl_sec_desc_scratch_len() to accurately
compute the final descriptor size beforehand, performs proper buffer
checking with smb2_calc_max_out_buf_len(), and uses exact-sized
allocation + iov pinning.

## Key facts

- **CVE ID:** CVE-2026-31432
- **Published:** 2026-04-22
- **CVSS severity:** HIGH
- **CVSS base score:** 8.8

## Primary sources

- NIST NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-31432

## Citation

> AI Analytics. CVE-2026-31432. Retrieved 2026-07-20 from https://api.ai-analytics.org/cve/CVE-2026-31432. Derived from NIST NVD. Licensed CC0.

---

*[Dataset catalog](https://api.ai-analytics.org/datasets/) · [AI Analytics](https://api.ai-analytics.org/) · CC0 1.0*