CVE-2024-26594

Source
https://cve.org/CVERecord?id=CVE-2024-26594
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-26594.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-26594
Downstream
Related
Published
2024-02-23T13:26:46.577Z
Modified
2026-05-18T05:56:02.588290782Z
Summary
ksmbd: validate mech token in session setup
Details

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: validate mech token in session setup

If client send invalid mech token in session setup request, ksmbd validate and make the error if it is invalid.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/26xxx/CVE-2024-26594.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0626e6641f6b467447c81dd7678a69c66f7746cf
Fixed
dd1de9268745f0eac83a430db7afc32cbd62e84b
Fixed
6eb8015492bcc84e40646390e50a862b2c0529c9
Fixed
a2b21ef1ea4cf632d19b3a7cc4d4245b8e63202a
Fixed
5e6dfec95833edc54c48605a98365a7325e5541e
Fixed
92e470163d96df8db6c4fa0f484e4a229edb903d

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-26594.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.15.0
Fixed
5.15.149
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.75
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.14
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.7.2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-26594.json"