# CVE-2026-31535

> Vulnerability · severity: **MEDIUM** (CVSS 4.7).

## Description

In the Linux kernel, the following vulnerability has been resolved:

smb: client: make use of smbdirect_socket.recv_io.credits.available

The logic off managing recv credits by counting posted recv_io and
granted credits is racy.

That's because the peer might already consumed a credit,
but between receiving the incoming recv at the hardware
and processing the completion in the 'recv_done' functions
we likely have a window where we grant credits, which
don't really exist.

So we better have a decicated counter for the
available credits, which will be incremented
when we posted new recv buffers and drained when
we grant the credits to the peer.

## Key facts

- **CVE ID:** CVE-2026-31535
- **Published:** 2026-04-24
- **CVSS severity:** MEDIUM
- **CVSS base score:** 4.7
- **CWE codes:** CWE-367

## Affected products

- `linux:linux_kernel`

## Primary sources

- NIST NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-31535

## Citation

> AI Analytics. CVE-2026-31535. Retrieved 2026-07-28 from https://api.ai-analytics.org/cve/CVE-2026-31535. Derived from NIST NVD. Licensed CC0.

---

*[Dataset catalog](https://api.ai-analytics.org/datasets/) · [AI Analytics](https://api.ai-analytics.org/) · CC0 1.0*