CVE-2026-23303 PUBLISHED

smb: client: Don't log plaintext credentials in cifs_set_cifscreds

Assigner: Linux
Reserved: 13.01.2026 Published: 25.03.2026 Updated: 25.03.2026

In the Linux kernel, the following vulnerability has been resolved:

smb: client: Don't log plaintext credentials in cifs_set_cifscreds

When debug logging is enabled, cifs_set_cifscreds() logs the key payload and exposes the plaintext username and password. Remove the debug log to avoid exposing credentials.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 8a8798a5ff90977d6459ce1d657cf8fe13a51e97 to ff0ece8ed04180c52167c003362284b23cf54e8d (excl.)
  • affected from 8a8798a5ff90977d6459ce1d657cf8fe13a51e97 to 3990f352bb0adc8688d0949a9c13e3110570eb61 (excl.)
  • affected from 8a8798a5ff90977d6459ce1d657cf8fe13a51e97 to b746a357abfb8fdb0a171d51ec5091e786d34be1 (excl.)
  • affected from 8a8798a5ff90977d6459ce1d657cf8fe13a51e97 to 2ef0fc3bf49db2b9df36d5f44508c9e384bfa2a1 (excl.)
  • affected from 8a8798a5ff90977d6459ce1d657cf8fe13a51e97 to 3e182701db612ddd794ccd5ed822e6cc1db2b972 (excl.)
  • affected from 8a8798a5ff90977d6459ce1d657cf8fe13a51e97 to 2f37dc436d4e61ff7ae0b0353cf91b8c10396e4d (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 3.3 is affected
  • unaffected from 0 to 3.3 (excl.)
  • unaffected from 6.1.167 to 6.1.* (incl.)
  • unaffected from 6.6.130 to 6.6.* (incl.)
  • unaffected from 6.12.77 to 6.12.* (incl.)
  • unaffected from 6.18.17 to 6.18.* (incl.)
  • unaffected from 6.19.7 to 6.19.* (incl.)
  • unaffected from 7.0-rc2 to * (incl.)

References