CVE-2026-31410: ksmbd: use volume UUID in FS_OBJECT_ID_INFORMATION
Published Apr 6, 2026
·Updated
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: use volume UUID in FSOBJECTIDINFORMATION
Use sb->suuid for a proper volume identifier as the primary choice. For filesystems that do not provide a UUID, fall back to stfs.ffsid obtained from vfsstatfs().
Affected Software
8 affected components
Linux ksmbd (Linux kernel)
Linux Linux kernel>=5.15<6.12.78
Linux Linux kernel>=6.13<6.18.20
Linux Linux kernel>=6.19<6.19.10
Linux Linux kernel=7.0-rc1
Linux Linux kernel=7.0-rc2
Linux Linux kernel=7.0-rc3
Linux Linux kernel=7.0-rc4
Event History
Apr 6, 2026
CVE Published
via MITRE·07:38 AM
Data Sourced
via MITRE·07:38 AM
Description
Data Sourced
via NVD·08:16 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-31410?
The severity of CVE-2026-31410 is rated as medium with a CVSS score of 5.5.
2
How do I fix CVE-2026-31410?
To fix CVE-2026-31410, you should apply the available patch released by the Linux kernel developers.
3
What software is affected by CVE-2026-31410?
CVE-2026-31410 affects the Linux kernel and specifically the ksmbd component.
4
How does CVE-2026-31410 impact systems?
CVE-2026-31410 can lead to improper identification of volume UUIDs, potentially affecting filesystem operations.
5
When was CVE-2026-31410 published?
CVE-2026-31410 was published on April 6, 2026.