CVE-2024-26594
This vulnerability allows an attacker to crash the ksmbd service in the Linux kernel by sending an invalid mech token during a session setup. The flaw can be exploited remotely without authentication or user interaction, causing a denial of service for SMB clients.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
All Linux kernel users running a kernel that does not include the ksmbd mech token validation fix, typically older kernel versions.
Real-world impact
An attacker could crash the ksmbd service, causing a denial of service for SMB clients and potentially disrupting network file sharing.
Why this severity
The CVSS score of 9.1 reflects that the vulnerability can be exploited remotely without authentication or user interaction, and it can cause a complete denial of service by crashing the ksmbd process.
What to do about it
- 01Upgrade the Linux kernel to a version that includes the ksmbd mech token validation fix.
- 02Reboot the system to load the updated kernel.
NVD description indicates the vulnerability has been resolved.
Timeline
- Feb 23, 2024 · Feb 23, 2024PublishedDisclosed and added to the National Vulnerability Database.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 5, 2026 · 9h agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.