PatchDay Alert

CVE

CVE-2026-31478

0field notes · 1digest CVSS 9.8


Daily digests

A buffer calculation bug in ksmbd (the in-kernel SMB3 server) can be triggered remotely. The CVSS 9.8 score signals unauthenticated remote exploitation is likely possible, though the terse commit message leaves exact impact unclear. If you expose ksmbd on any network, treat this as a potential remote code execution path.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.