CVE-2026-23364
published 2026-03-25CVE-2026-23364: In the Linux kernel, the following vulnerability has been resolved: ksmbd: Compare MACs in constant time To prevent timing attacks, MAC comparisons need to be…
PriorityP340high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
0.39%
31.4th percentile
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: Compare MACs in constant time
To prevent timing attacks, MAC comparisons need to be constant-time.
Replace the memcmp() with the correct function, crypto_memneq().
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.19.8-1 (forky) | linux 6.19.8-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < 8a665d733940592e671ec6afadcd0be80a091a80 | 8a665d733940592e671ec6afadcd0be80a091a80 |
| linux | linux | >= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < cd52a0e309659537048a864211abc3ea4c5caa63 | cd52a0e309659537048a864211abc3ea4c5caa63 |
| linux | linux | >= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < 307afccb751f542246bd5dc68a2c1ffe1a78418c | 307afccb751f542246bd5dc68a2c1ffe1a78418c |
| linux | linux | >= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < 2cdc56ed67615ba0921383a688f24415ebe065f3 | 2cdc56ed67615ba0921383a688f24415ebe065f3 |
| linux | linux | >= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < 93c0a22fec914ec4b697e464895a0f594e29fb28 | 93c0a22fec914ec4b697e464895a0f594e29fb28 |
| linux | linux | >= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < f4588b85efd6007d46b80aa1b9fb746628ffb3dc | f4588b85efd6007d46b80aa1b9fb746628ffb3dc |
| linux | linux | >= e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 < c5794709bc9105935dbedef8b9cf9c06f2b559fa | c5794709bc9105935dbedef8b9cf9c06f2b559fa |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.19.8-1 | 6.19.8-1 |
| linux | linux_kernel | >= 5.15.0 < 6.1.167 | 6.1.167 |
| linux | linux_kernel | >= 5.15.1 < 6.1.167 | 6.1.167 |
| linux | linux_kernel | >= 6.13 < 6.18.19 | 6.18.19 |
| linux | linux_kernel | >= 6.13.0 < 6.18.19 | 6.18.19 |
| linux | linux_kernel | >= 6.19 < 6.19.7 | 6.19.7 |
| linux | linux_kernel | >= 6.19.0 < 6.19.7 | 6.19.7 |
| linux | linux_kernel | >= 6.2 < 6.6.130 | 6.6.130 |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
osv7.4HIGH
vendor_debian7.4HIGH
vendor_redhat7.4HIGH
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: ksmbd: Compare MACs in constant time
vendor_redhat·2026-03-25·CVSS 7.4
CVE-2026-23364 [HIGH] CWE-208 kernel: ksmbd: Compare MACs in constant time
kernel: ksmbd: Compare MACs in constant time
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: Compare MACs in constant time
To prevent timing attacks, MAC comparisons need to be constant-time.
Replace the memcmp() with the correct function, crypto_memneq().
A flaw was found in ksmbd, a Linux kernel module. This vulnerability stems from the use of a non-constant time memory comparison function when verifying Message Authentication Codes (MACs). A remote attacker could exploit this timing difference to conduct a timing attack, potentially leading to the disclosure of sensitive information.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not af
Microsoft
ksmbd: Compare MACs in constant time
vendor_msrc·2026-03-10·CVSS 5.5
CVE-2026-23364 [HIGH] ksmbd: Compare MACs in constant time
ksmbd: Compare MACs in constant time
Mariner: Mariner
Linux: Linux
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Debian
CVE-2026-23364: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: Comp...
vendor_debian·2026·CVSS 7.4
CVE-2026-23364 [HIGH] CVE-2026-23364: linux - In the Linux kernel, the following vulnerability has been resolved: ksmbd: Comp...
In the Linux kernel, the following vulnerability has been resolved: ksmbd: Compare MACs in constant time To prevent timing attacks, MAC comparisons need to be constant-time. Replace the memcmp() with the correct function, crypto_memneq().
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 6.19.8-1)
sid: resolved (fixed in 6.19.8-1)
trixie: open
VulDB
Linux Kernel up to 7.0-rc1 ksmbd memcmp timing discrepancy (Nessus ID 311783 / WID-SEC-2026-0861)
vuldb·2026-06-20·CVSS 7.4
CVE-2026-23364 [HIGH] Linux Kernel up to 7.0-rc1 ksmbd memcmp timing discrepancy (Nessus ID 311783 / WID-SEC-2026-0861)
A vulnerability labeled as problematic has been found in Linux Kernel up to 7.0-rc1. Affected by this issue is the function memcmp of the component ksmbd. Such manipulation leads to observable timing discrepancy.
This vulnerability is referenced as CVE-2026-23364. The attack needs to be initiated within the local network. No exploit is available.
The affected component should be upgraded.
OSV
CVE-2026-23364: In the Linux kernel, the following vulnerability has been resolved: ksmbd: Compare MACs in constant time To prevent timing attacks, MAC comparisons ne
osv·2026-03-25·CVSS 7.4
CVE-2026-23364 [HIGH] CVE-2026-23364: In the Linux kernel, the following vulnerability has been resolved: ksmbd: Compare MACs in constant time To prevent timing attacks, MAC comparisons ne
In the Linux kernel, the following vulnerability has been resolved: ksmbd: Compare MACs in constant time To prevent timing attacks, MAC comparisons need to be constant-time. Replace the memcmp() with the correct function, crypto_memneq().
GHSA
GHSA-4mmg-5v66-42gx: In the Linux kernel, the following vulnerability has been resolved:
ksmbd: Compare MACs in constant time
To prevent timing attacks, MAC comparisons
ghsa_unreviewed·2026-03-25
CVE-2026-23364 [HIGH] GHSA-4mmg-5v66-42gx: In the Linux kernel, the following vulnerability has been resolved:
ksmbd: Compare MACs in constant time
To prevent timing attacks, MAC comparisons
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: Compare MACs in constant time
To prevent timing attacks, MAC comparisons need to be constant-time.
Replace the memcmp() with the correct function, crypto_memneq().
OSV
ksmbd: Compare MACs in constant time
osv·2026-03-25·CVSS 7.4
CVE-2026-23364 [HIGH] ksmbd: Compare MACs in constant time
ksmbd: Compare MACs in constant time
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: Compare MACs in constant time
To prevent timing attacks, MAC comparisons need to be constant-time.
Replace the memcmp() with the correct function, crypto_memneq().
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/2cdc56ed67615ba0921383a688f24415ebe065f3https://git.kernel.org/stable/c/307afccb751f542246bd5dc68a2c1ffe1a78418chttps://git.kernel.org/stable/c/8a665d733940592e671ec6afadcd0be80a091a80https://git.kernel.org/stable/c/93c0a22fec914ec4b697e464895a0f594e29fb28https://git.kernel.org/stable/c/c5794709bc9105935dbedef8b9cf9c06f2b559fahttps://git.kernel.org/stable/c/cd52a0e309659537048a864211abc3ea4c5caa63https://git.kernel.org/stable/c/f4588b85efd6007d46b80aa1b9fb746628ffb3dc
2026-03-25
Published