CVE-2026-23303

Analyzed
Published: 25 Mar 2026, 10:26
Last modified:11 May 2026, 22:04

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.12% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

25 Mar 2026, 10:26
Published
Vulnerability first disclosed
11 May 2026, 22:04
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: Don't log plaintext credentials in cifs_set_cifscreds When debug logging is enabled, cifs_set_cifscreds() logs the key payload and exposes the plaintext username and password. Remove the debug log to avoid exposing credentials.

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.12% Percentile: 2%

Affected Systems

  • linuxlinux

    ≥ 8a8798a5ff90977d6459ce1d657cf8fe13a51e97, < e5a3b11e07b335006371915b2da47b6056c9e3bc | ≥ 8a8798a5ff90977d6459ce1d657cf8fe13a51e97, < 54c570de9a35860dfa85fe668f23ddfda8cc7e26 | ≥ 8a8798a5ff90977d6459ce1d657cf8fe13a51e97, < ff0ece8ed04180c52167c003362284b23cf54e8d | ≥ 8a8798a5ff90977d6459ce1d657cf8fe13a51e97, < 3990f352bb0adc8688d0949a9c13e3110570eb61 | ≥ 8a8798a5ff90977d6459ce1d657cf8fe13a51e97, < b746a357abfb8fdb0a171d51ec5091e786d34be1 | ≥ 8a8798a5ff90977d6459ce1d657cf8fe13a51e97, < 2ef0fc3bf49db2b9df36d5f44508c9e384bfa2a1 | ≥ 8a8798a5ff90977d6459ce1d657cf8fe13a51e97, < 3e182701db612ddd794ccd5ed822e6cc1db2b972 | ≥ 8a8798a5ff90977d6459ce1d657cf8fe13a51e97, < 2f37dc436d4e61ff7ae0b0353cf91b8c10396e4d | 3.3

  • linuxlinux kernel

    ≥ 3.3.1, < 5.10.253 | ≥ 5.11, < 5.15.203 | ≥ 5.16, < 6.1.167 | ≥ 6.2, < 6.6.130 | ≥ 6.7, < 6.12.77 | ≥ 6.13, < 6.18.17 | ≥ 6.19, < 6.19.7 | 3.3 | 3.3:rc2 | 3.3:rc3 | 3.3:rc4 | 3.3:rc5 | 3.3:rc6 | 3.3:rc7 | 7.0:rc1

References (8)