cbcvebase.
CVE-2024-26594
published 2024-02-23

CVE-2024-26594: In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate mech token in session setup If client send invalid mech token in session…

PriorityP349high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
78.39%
99.5th percentile
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate mech token in session setup If client send invalid mech token in session setup request, ksmbd validate and make the error if it is invalid.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.76-1 (bookworm)linux 6.1.76-1 (bookworm)
linuxlinux
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < dd1de9268745f0eac83a430db7afc32cbd62e84bdd1de9268745f0eac83a430db7afc32cbd62e84b
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 6eb8015492bcc84e40646390e50a862b2c0529c96eb8015492bcc84e40646390e50a862b2c0529c9
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < a2b21ef1ea4cf632d19b3a7cc4d4245b8e63202aa2b21ef1ea4cf632d19b3a7cc4d4245b8e63202a
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 5e6dfec95833edc54c48605a98365a7325e5541e5e6dfec95833edc54c48605a98365a7325e5541e
linuxlinux>= 0626e6641f6b467447c81dd7678a69c66f7746cf < 92e470163d96df8db6c4fa0f484e4a229edb903d92e470163d96df8db6c4fa0f484e4a229edb903d
linuxlinux_kernel< 5.15.1495.15.149
linuxlinux_kernel>= 0 < 6.1.76-16.1.76-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 5.15.0-106.1165.15.0-106.116
linuxlinux_kernel>= 5.16.0 < 6.1.756.1.75
linuxlinux_kernel>= 6.2.0 < 6.6.146.6.14
linuxlinux_kernel>= 6.7.0 < 6.7.26.7.2
msrccbl2_hyperv-daemons_5.15.148.2-1_on_cbl_mariner_2.0
msrccbl2_hyperv-daemons_5.15.153.1-1_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64

Detection & IOCsextracted from sources · hover to see the quote

  • Target the ksmbd SMB server component in the Linux kernel; the vulnerability is triggered by a client sending an invalid mech token during the SMB session setup negotiation phase.
  • ·Red Hat Enterprise Linux 6, 7, 8, and 9 (kernel and kernel-rt packages) are confirmed NOT affected by this CVE.
  • ·Debian bookworm is fixed in kernel 6.1.76-1; Debian forky, sid, and trixie are fixed in 6.6.15-1. Systems running earlier kernel versions with ksmbd enabled remain vulnerable.
  • ·Azure Linux (CBL-Mariner) is identified as a Microsoft product affected by this vulnerability; customers should upgrade per the Azure Linux upgrade tutorial.

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian7.1HIGH
vendor_msrc7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.