Home

Description

In the Linux kernel, the following vulnerability has been resolved: smb: client: Don't log plaintext credentials in cifs_set_cifscreds When debug logging is enabled, cifs_set_cifscreds() logs the key payload and exposes the plaintext username and password. Remove the debug log to avoid exposing credentials.

PUBLISHED Reserved 2026-01-13 | Published 2026-03-25 | Updated 2026-05-11 | Assigner Linux

Product status

Default status
unaffected

8a8798a5ff90977d6459ce1d657cf8fe13a51e97 (git) before e5a3b11e07b335006371915b2da47b6056c9e3bc
affected

8a8798a5ff90977d6459ce1d657cf8fe13a51e97 (git) before 54c570de9a35860dfa85fe668f23ddfda8cc7e26
affected

8a8798a5ff90977d6459ce1d657cf8fe13a51e97 (git) before ff0ece8ed04180c52167c003362284b23cf54e8d
affected

8a8798a5ff90977d6459ce1d657cf8fe13a51e97 (git) before 3990f352bb0adc8688d0949a9c13e3110570eb61
affected

8a8798a5ff90977d6459ce1d657cf8fe13a51e97 (git) before b746a357abfb8fdb0a171d51ec5091e786d34be1
affected

8a8798a5ff90977d6459ce1d657cf8fe13a51e97 (git) before 2ef0fc3bf49db2b9df36d5f44508c9e384bfa2a1
affected

8a8798a5ff90977d6459ce1d657cf8fe13a51e97 (git) before 3e182701db612ddd794ccd5ed822e6cc1db2b972
affected

8a8798a5ff90977d6459ce1d657cf8fe13a51e97 (git) before 2f37dc436d4e61ff7ae0b0353cf91b8c10396e4d
affected

Default status
affected

3.3
affected

Any version before 3.3
unaffected

5.10.253 (semver)
unaffected

5.15.203 (semver)
unaffected

6.1.167 (semver)
unaffected

6.6.130 (semver)
unaffected

6.12.77 (semver)
unaffected

6.18.17 (semver)
unaffected

6.19.7 (semver)
unaffected

7.0 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/e5a3b11e07b335006371915b2da47b6056c9e3bc

git.kernel.org/...c/54c570de9a35860dfa85fe668f23ddfda8cc7e26

git.kernel.org/...c/ff0ece8ed04180c52167c003362284b23cf54e8d

git.kernel.org/...c/3990f352bb0adc8688d0949a9c13e3110570eb61

git.kernel.org/...c/b746a357abfb8fdb0a171d51ec5091e786d34be1

git.kernel.org/...c/2ef0fc3bf49db2b9df36d5f44508c9e384bfa2a1

git.kernel.org/...c/3e182701db612ddd794ccd5ed822e6cc1db2b972

git.kernel.org/...c/2f37dc436d4e61ff7ae0b0353cf91b8c10396e4d

cve.org (CVE-2026-23303)

nvd.nist.gov (CVE-2026-23303)

Download JSON