Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-26594

65
FAUCET Score

CVE-2024-26594 is a vulnerability in the Linux kernel's ksmbd module, affecting Linux systems. It arises from insufficient validation of mechanism tokens during session setup, allowing an attacker to potentially cause a denial of service or information disclosure. With a CVSS score of 7.1 (HIGH), this vulnerability has a local attack vector, low attack complexity, and requires low privileges, but does not require user interaction. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 5.15.149CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16.0, < 6.1.75CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.2.0, < 6.6.14CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.7.0, < 6.7.2CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.1HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
78.39%
Probability of exploitation in next 30 days
EPSS Percentile
99.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.7839 is in the 100th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

linuxpatch availablevia osv
Product: KernelFixed in: 5.15.149
linuxpatch availablevia osv
Product: KernelFixed in: 6.1.75
linuxpatch availablevia osv
Product: KernelFixed in: 6.6.14
linuxpatch availablevia osv
Product: KernelFixed in: 6.7.2
microsoftpatch availablevia msrc
Product: 17427-16823Fixed in: 5.15.153.1-1
microsoftpatch availablevia msrc
Product: 20072-17086Fixed in: 5.15.153.1-1
microsoftpatch availablevia msrc
Product: cbl2 hyperv-daemons 5.15.153.1-1 on CBL Mariner 2.0Fixed in: 5.15.153.1-1
microsoftpatch availablevia msrc
Product: cbl2 hyperv-daemons 5.15.148.2-1 on CBL Mariner 2.0Fixed in: 5.15.153.1-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 5.15.153.1-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 5.15.153.1-1

Vendor Advisories (4)

microsoft2024-Mar/CVE-2024-26594

CVE-2024-26594

Mar 12, 2024
linuxCVE-2024-26594

ksmbd: validate mech token in session setup

Feb 23, 2024
redhatCVE-2024-26594Moderate

kernel: ksmbd: validate mech token in session setup

Feb 23, 2024
microsoft2024-Feb/CVE-2024-26594Important

ksmbd: validate mech token in session setup

Feb 13, 2024

References

git.kernel.org / stable/c/5e6dfec95833edc54c48605a98365a7325e5541e
Patch
git.kernel.org / stable/c/6eb8015492bcc84e40646390e50a862b2c0529c9
Patch
git.kernel.org / stable/c/92e470163d96df8db6c4fa0f484e4a229edb903d
Patch
git.kernel.org / stable/c/a2b21ef1ea4cf632d19b3a7cc4d4245b8e63202a
Patch
git.kernel.org / stable/c/dd1de9268745f0eac83a430db7afc32cbd62e84b
Patch