CVE-2026-23364

HIGH EPSS 31.0%
Published Mar 25, 20263mo ago · Modified Jun 19, 20261w ago
7.4 CVSS 3.1
High
Find Similar
Published Mar 25, 2026 3mo ago
Last Modified Jun 19, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: Compare MACs in constant time To prevent timing attacks, MAC comparisons need to be constant-time. Replace the memcmp() with the correct function, crypto_memneq().

CVSS Details

Base Score
7.4
Exploitability
2.2
Impact
5.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector Network
Attack Complexity High
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability None

Threat Intelligence

EPSS Exploit Probability
31.0% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Affected Products 13

VendorProductVersionRange
linuxlinux_kernel*≥5.15.1  –  <6.1.167
linuxlinux_kernel*≥6.2  –  <6.6.130
linuxlinux_kernel*≥6.7  –  <6.12.78
linuxlinux_kernel*≥6.13  –  <6.18.19
linuxlinux_kernel*≥6.19  –  <6.19.7
linuxlinux_kernel5.15any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any

References 7

  • git.kernel.org https://git.kernel.org/stable/c/2cdc56ed67615ba0921383a688f24415ebe065f3
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/307afccb751f542246bd5dc68a2c1ffe1a78418c
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8a665d733940592e671ec6afadcd0be80a091a80
  • git.kernel.org https://git.kernel.org/stable/c/93c0a22fec914ec4b697e464895a0f594e29fb28
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c5794709bc9105935dbedef8b9cf9c06f2b559fa
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/cd52a0e309659537048a864211abc3ea4c5caa63
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f4588b85efd6007d46b80aa1b9fb746628ffb3dc
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/2cdc56ed67615ba0921383a688f24415ebe065f3
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/307afccb751f542246bd5dc68a2c1ffe1a78418c
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/93c0a22fec914ec4b697e464895a0f594e29fb28
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c5794709bc9105935dbedef8b9cf9c06f2b559fa
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/cd52a0e309659537048a864211abc3ea4c5caa63
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f4588b85efd6007d46b80aa1b9fb746628ffb3dc
    Patch