Observable discrepancy in Linux kernel - CVE-2026-23364
Published: March 25, 2026
Vulnerability details
The vulnerability allows a local user to obtain sensitive information.
The vulnerability exists due to improper timing handling in the ksmbd component when comparing message authentication codes (MACs). A local user can leverage timing differences during MAC comparison to infer sensitive information.
Exploitation requires local access and the ability to trigger MAC comparisons through the ksmbd subsystem.
Affected software
Debian Linux
openEuler
Ubuntu
perf
kernel
python3-perf-debuginfo
python3-perf
perf-debuginfo
kernel-tools-devel
kernel-tools-debuginfo
kernel-tools
kernel-source
kernel-headers
kernel-devel
kernel-debugsource
kernel-debuginfo
bpftool-debuginfo
bpftool
linux (Debian package)
linux (Ubuntu package)
linux-fips (Ubuntu package)
linux-hwe-6.8 (Ubuntu package)
linux-ibm (Ubuntu package)
linux-oracle-6.8 (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-aws-6.8 (Ubuntu package)
linux-aws (Ubuntu package)
linux-raspi (Ubuntu package)
linux-azure-fde (Ubuntu package)
linux-azure-fde-6.8 (Ubuntu package)
linux-azure (Ubuntu package)
linux-azure-fips (Ubuntu package)
linux-gcp-fips (Ubuntu package)
How to mitigate CVE-2026-23364
perf - update to 5.10.0-308.0.0.211
kernel - update to 5.10.0-308.0.0.211
python3-perf-debuginfo - update to 5.10.0-308.0.0.211
python3-perf - update to 5.10.0-308.0.0.211
perf-debuginfo - update to 5.10.0-308.0.0.211
kernel-tools-devel - update to 5.10.0-308.0.0.211
kernel-tools-debuginfo - update to 5.10.0-308.0.0.211
kernel-tools - update to 5.10.0-308.0.0.211
kernel-source - update to 5.10.0-308.0.0.211
kernel-headers - update to 5.10.0-308.0.0.211
kernel-devel - update to 5.10.0-308.0.0.211
kernel-debugsource - update to 5.10.0-308.0.0.211
kernel-debuginfo - update to 5.10.0-308.0.0.211
bpftool-debuginfo - update to 5.10.0-308.0.0.211
bpftool - update to 5.10.0-308.0.0.211
linux (Debian package) - addressed in versions 6.1.170-1, 6.12.85-1
linux (Ubuntu package) - addressed in versions 6.8.0-136.136, 6.8.0-1046.50, 6.8.0-1059.67, 6.8.0-1064.72, 6.8.0-1064.72~22.04.1, 6.8.1-1056.57, 6.8.1-1056.57~22.04.2
linux-fips (Ubuntu package) - addressed in versions 6.8.0-136.136+fips2, 6.8.0-136.136.2, 6.8.0-136.136.2~22.04.1, 6.8.0-1058.61
linux-hwe-6.8 (Ubuntu package) - update to 6.8.0-136.136~22.04.1
linux-ibm (Ubuntu package) - addressed in versions 6.8.0-1030.31, 6.8.0-1033.34, 6.8.0-1061.62, 6.8.0-1061.62~22.04.1
linux-oracle-6.8 (Ubuntu package) - update to 6.8.0-1058.61~22.04.1
linux-nvidia (Ubuntu package) - addressed in versions 6.8.0-1059.62, 6.8.0-1059.62.1, 6.8.0-1059.62~22.04.1
linux-aws-6.8 (Ubuntu package) - addressed in versions 6.8.0-1061.64+fips1, 6.8.0-1061.64~22.04.1
linux-aws (Ubuntu package) - update to 6.8.0-1061.64+1
linux-raspi (Ubuntu package) - addressed in versions 6.8.0-1061.65, 6.8.0-2050.52
linux-azure-fde (Ubuntu package) - update to 6.8.0-1062.69
linux-azure-fde-6.8 (Ubuntu package) - update to 6.8.0-1062.69~22.04.1
linux-azure (Ubuntu package) - addressed in versions 6.8.0-1063.71, 6.8.0-1063.71~22.04.1
linux-azure-fips (Ubuntu package) - update to 6.8.0-1063.71+fips2
linux-gcp-fips (Ubuntu package) - update to 6.8.0-1064.72+fips1
External References
- https://git.kernel.org/stable/c/2cdc56ed67615ba0921383a688f24415ebe065f3
- https://git.kernel.org/stable/c/307afccb751f542246bd5dc68a2c1ffe1a78418c
- https://git.kernel.org/stable/c/93c0a22fec914ec4b697e464895a0f594e29fb28
- https://git.kernel.org/stable/c/c5794709bc9105935dbedef8b9cf9c06f2b559fa
- https://git.kernel.org/stable/c/cd52a0e309659537048a864211abc3ea4c5caa63
- https://git.kernel.org/stable/c/f4588b85efd6007d46b80aa1b9fb746628ffb3dc
Related Security Bulletins
- Observable discrepancy in Linux kernel smb server
- openEuler 22.03 LTS SP4 update for kernel
- Debian update for linux
- Debian update for linux
- Ubuntu update for linux
- Ubuntu update for linux-gcp-fips
- Ubuntu update for linux-oracle-6.8
- Ubuntu update for linux-fips
- Ubuntu update for linux-nvidia
- Ubuntu update for linux-azure-fde-6.8
- Ubuntu update for linux-azure-fips
- Ubuntu update for linux-azure-fde
- Ubuntu update for linux-azure
- Ubuntu update for linux-aws
- Ubuntu update for linux-hwe-6.8
- Ubuntu update for linux-aws-6.8
- Ubuntu update for linux-ibm
- Ubuntu update for linux-raspi