PatchDay Alert

CVE

CVE-2026-31718

0field notes · 1digest CVSS 9.8


Daily digests

A use-after-free bug in ksmbd (the in-kernel SMB server on Linux) lets a remote attacker potentially execute code or crash the system by triggering a race condition through durable file handle scavenging. CVSS 9.8 makes this critical. If you expose ksmbd to the network, an attacker may not need credentials to trigger it.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.