cbcvebase.
CVE-2026-23303
published 2026-03-25

CVE-2026-23303: In the Linux kernel, the following vulnerability has been resolved: smb: client: Don't log plaintext credentials in cifs_set_cifscreds When debug logging is…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.4th percentile
In the Linux kernel, the following vulnerability has been resolved: smb: client: Don't log plaintext credentials in cifs_set_cifscreds When debug logging is enabled, cifs_set_cifscreds() logs the key payload and exposes the plaintext username and password. Remove the debug log to avoid exposing credentials.

Affected

63 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.8-1 (forky)linux 6.19.8-1 (forky)
linuxlinux
linuxlinux>= 8a8798a5ff90977d6459ce1d657cf8fe13a51e97 < e5a3b11e07b335006371915b2da47b6056c9e3bce5a3b11e07b335006371915b2da47b6056c9e3bc
linuxlinux>= 8a8798a5ff90977d6459ce1d657cf8fe13a51e97 < 54c570de9a35860dfa85fe668f23ddfda8cc7e2654c570de9a35860dfa85fe668f23ddfda8cc7e26
linuxlinux>= 8a8798a5ff90977d6459ce1d657cf8fe13a51e97 < ff0ece8ed04180c52167c003362284b23cf54e8dff0ece8ed04180c52167c003362284b23cf54e8d
linuxlinux>= 8a8798a5ff90977d6459ce1d657cf8fe13a51e97 < 3990f352bb0adc8688d0949a9c13e3110570eb613990f352bb0adc8688d0949a9c13e3110570eb61
linuxlinux>= 8a8798a5ff90977d6459ce1d657cf8fe13a51e97 < b746a357abfb8fdb0a171d51ec5091e786d34be1b746a357abfb8fdb0a171d51ec5091e786d34be1
linuxlinux>= 8a8798a5ff90977d6459ce1d657cf8fe13a51e97 < 2ef0fc3bf49db2b9df36d5f44508c9e384bfa2a12ef0fc3bf49db2b9df36d5f44508c9e384bfa2a1
linuxlinux>= 8a8798a5ff90977d6459ce1d657cf8fe13a51e97 < 3e182701db612ddd794ccd5ed822e6cc1db2b9723e182701db612ddd794ccd5ed822e6cc1db2b972
linuxlinux>= 8a8798a5ff90977d6459ce1d657cf8fe13a51e97 < 2f37dc436d4e61ff7ae0b0353cf91b8c10396e4d2f37dc436d4e61ff7ae0b0353cf91b8c10396e4d
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.8-16.19.8-1
linuxlinux_kernel>= 3.3.0 < 6.1.1676.1.167
linuxlinux_kernel>= 3.3.1 < 5.10.2535.10.253
linuxlinux_kernel>= 5.11 < 5.15.2035.15.203
linuxlinux_kernel>= 5.16 < 6.1.1676.1.167
linuxlinux_kernel>= 6.13 < 6.18.176.18.17
linuxlinux_kernel>= 6.13.0 < 6.18.176.18.17
linuxlinux_kernel>= 6.19 < 6.19.76.19.7
linuxlinux_kernel>= 6.19.0 < 6.19.76.19.7
linuxlinux_kernel>= 6.2 < 6.6.1306.6.130
linuxlinux_kernel>= 6.2.0 < 6.6.1306.6.130
linuxlinux_kernel>= 6.7 < 6.12.776.12.77
linuxlinux_kernel>= 6.7.0 < 6.12.776.12.77

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_ubuntu7.1HIGH
vendor_msrc5.5MEDIUM
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.