CVE-2024-26594: critical vulnerability in Linux
ksmbd: validate mech token in session setup
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
The ksmbd SMB server in Linux was not properly validating authentication tokens sent by clients during session setup, allowing invalid tokens to bypass validation. This could allow attackers to establish unauthorized connections.
ksmbd failed to validate the mechanism token (mech token) in the SMB session setup request, allowing clients to send malformed or invalid authentication tokens without proper rejection. An unauthenticated attacker can trigger this by sending a crafted session setup request with an invalid mech token, potentially bypassing authentication controls.
In the same product, most dangerous first.