Status: UPDATED | Advisory ID: CVE-2026-31693
| CVE | CVE-2026-31693 |
| CVSS Score / Version | 7.8 (High) / CVSS v3.1 |
| Updated | 2026-06-17 |
| CVSS Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Linux Linux Kernel |
| Classified as | CWE-908 (Use of Uninitialized Resource) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Linux | Linux Kernel |
| Subsystems | General OT |
| Sectors | All Sectors |
In the Linux kernel, the following vulnerability has been resolved:
cifs: some missing initializations on replay
In several places in the code, we have a label to signify
the start of the code where a request can be replayed if
necessary. However, some of these places were missing the
necessary reinitializations of certain local variables
before replay.
This change makes sure that these variables get initialized
after the label. (NVD)
Monitor Linux's web page for any future patch releases.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-31693 |
| CVE | https://www.cve.org/CVERecord?id=CVE-2026-31693 |