Observable discrepancy in Linux kernel - CVE-2026-23364

 

Observable discrepancy in Linux kernel - CVE-2026-23364

Published: March 25, 2026


Vulnerability identifier: #VU124479
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-23364
CWE-ID: CWE-203
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to obtain sensitive information.

The vulnerability exists due to improper timing handling in the ksmbd component when comparing message authentication codes (MACs). A local user can leverage timing differences during MAC comparison to infer sensitive information.

Exploitation requires local access and the ability to trigger MAC comparisons through the ksmbd subsystem.


Affected software

Linux kernel
Debian Linux
openEuler
Ubuntu
bpftool
bpftool-debuginfo
kernel-debuginfo
kernel-debugsource
kernel-devel
kernel-headers
kernel-source
kernel-tools
kernel-tools-debuginfo
kernel-tools-devel
perf
perf-debuginfo
python3-perf
python3-perf-debuginfo
kernel
linux (Debian package)
linux (Ubuntu package)
linux-fips (Ubuntu package)
linux-hwe-6.8 (Ubuntu package)
linux-ibm (Ubuntu package)
linux-oracle-6.8 (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-aws-6.8 (Ubuntu package)
linux-aws (Ubuntu package)
linux-azure-fde (Ubuntu package)
linux-azure-fde-6.8 (Ubuntu package)
linux-azure (Ubuntu package)
linux-azure-fips (Ubuntu package)
linux-gcp-fips (Ubuntu package)

How to mitigate CVE-2026-23364

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
bpftool - update to 5.10.0-308.0.0.211
bpftool-debuginfo - update to 5.10.0-308.0.0.211
kernel-debuginfo - update to 5.10.0-308.0.0.211
kernel-debugsource - update to 5.10.0-308.0.0.211
kernel-devel - update to 5.10.0-308.0.0.211
kernel-headers - update to 5.10.0-308.0.0.211
kernel-source - update to 5.10.0-308.0.0.211
kernel-tools - update to 5.10.0-308.0.0.211
kernel-tools-debuginfo - update to 5.10.0-308.0.0.211
kernel-tools-devel - update to 5.10.0-308.0.0.211
perf - update to 5.10.0-308.0.0.211
perf-debuginfo - update to 5.10.0-308.0.0.211
python3-perf - update to 5.10.0-308.0.0.211
python3-perf-debuginfo - update to 5.10.0-308.0.0.211
kernel - update to 5.10.0-308.0.0.211
linux (Debian package) - addressed in versions 6.1.170-1, 6.12.85-1
linux (Ubuntu package) - addressed in versions 6.8.0-136.136, 6.8.0-1046.50, 6.8.0-1059.67, 6.8.0-1064.72, 6.8.0-1064.72~22.04.1, 6.8.1-1056.57, 6.8.1-1056.57~22.04.2
linux-fips (Ubuntu package) - addressed in versions 6.8.0-136.136+fips2, 6.8.0-136.136.2, 6.8.0-136.136.2~22.04.1, 6.8.0-1058.61
linux-hwe-6.8 (Ubuntu package) - update to 6.8.0-136.136~22.04.1
linux-ibm (Ubuntu package) - addressed in versions 6.8.0-1030.31, 6.8.0-1033.34, 6.8.0-1061.62, 6.8.0-1061.62~22.04.1
linux-oracle-6.8 (Ubuntu package) - update to 6.8.0-1058.61~22.04.1
linux-nvidia (Ubuntu package) - addressed in versions 6.8.0-1059.62, 6.8.0-1059.62.1, 6.8.0-1059.62~22.04.1
linux-aws-6.8 (Ubuntu package) - addressed in versions 6.8.0-1061.64+fips1, 6.8.0-1061.64~22.04.1
linux-aws (Ubuntu package) - update to 6.8.0-1061.64+1
linux-azure-fde (Ubuntu package) - update to 6.8.0-1062.69
linux-azure-fde-6.8 (Ubuntu package) - update to 6.8.0-1062.69~22.04.1
linux-azure (Ubuntu package) - addressed in versions 6.8.0-1063.71, 6.8.0-1063.71~22.04.1
linux-azure-fips (Ubuntu package) - update to 6.8.0-1063.71+fips2
linux-gcp-fips (Ubuntu package) - update to 6.8.0-1064.72+fips1

External References

Related Security Bulletins