cbcvebase.
CVE-2026-23364
published 2026-03-25

CVE-2026-23364: In the Linux kernel, the following vulnerability has been resolved: ksmbd: Compare MACs in constant time To prevent timing attacks, MAC comparisons need to be…

PriorityP340high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
0.39%
31.4th percentile
In the Linux kernel, the following vulnerability has been resolved: ksmbd: Compare MACs in constant time To prevent timing attacks, MAC comparisons need to be constant-time. Replace the memcmp() with the correct function, crypto_memneq().

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.8-1 (forky)linux 6.19.8-1 (forky)
linuxlinux
linuxlinux>= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < 8a665d733940592e671ec6afadcd0be80a091a808a665d733940592e671ec6afadcd0be80a091a80
linuxlinux>= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < cd52a0e309659537048a864211abc3ea4c5caa63cd52a0e309659537048a864211abc3ea4c5caa63
linuxlinux>= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < 307afccb751f542246bd5dc68a2c1ffe1a78418c307afccb751f542246bd5dc68a2c1ffe1a78418c
linuxlinux>= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < 2cdc56ed67615ba0921383a688f24415ebe065f32cdc56ed67615ba0921383a688f24415ebe065f3
linuxlinux>= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < 93c0a22fec914ec4b697e464895a0f594e29fb2893c0a22fec914ec4b697e464895a0f594e29fb28
linuxlinux>= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < f4588b85efd6007d46b80aa1b9fb746628ffb3dcf4588b85efd6007d46b80aa1b9fb746628ffb3dc
linuxlinux>= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < c5794709bc9105935dbedef8b9cf9c06f2b559fac5794709bc9105935dbedef8b9cf9c06f2b559fa
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.8-16.19.8-1
linuxlinux_kernel>= 5.15.0 < 6.1.1676.1.167
linuxlinux_kernel>= 5.15.1 < 6.1.1676.1.167
linuxlinux_kernel>= 6.13 < 6.18.196.18.19
linuxlinux_kernel>= 6.13.0 < 6.18.196.18.19
linuxlinux_kernel>= 6.19 < 6.19.76.19.7
linuxlinux_kernel>= 6.19.0 < 6.19.76.19.7
linuxlinux_kernel>= 6.2 < 6.6.1306.6.130

CVSS provenance

nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
osv7.4HIGH
vendor_debian7.4HIGH
vendor_redhat7.4HIGH
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.