CVE-2026-23303Patch(linux / linux_kernel)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: smb: client: Don't log plaintext credentials in cifs_set_cifscreds When debug logging is enabled, cifs_set_cifscreds() logs the key payload and exposes the plaintext username and password. Remove the debug log to avoid exposing credentials.

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-03-25); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
linux_kernel

2 versions affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-25: 2Mentions · 2026-03-28: 1Mentions · 2026-06-17: 1Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-06-17: 1Technical Details · 2026-03-25: 2Technical Details · 2026-06-17: 103-2503-2806-17
Signal classification2 categories
Patch
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-252
Patch2
2026-03-281
General1
2026-06-171
Patch1
Full discourse4 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    #SUSE Linux Micro 6.0 e 6.1 receberam correção para 98 falhas no kernel. A CVE-2026-23303 expõe credenciais SMB em texto puro quando debug logging está ativo. Saiba mais: -> http://tinyurl.com/y6h9bfcf https://t.co/KIgyHVOdki

    Post summary

    SUSE Linux Micro 6.0 and 6.1 have applied a kernel patch addressing 98 vulnerabilities, including CVE‑2026‑23303, which reveals SMB credentials in plaintext when debug logging is active.

    1001061
    1.5K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-23303 In the Linux kernel, the following vulnerability has been resolved: smb: client: Don't log plaintext credentials in cifs_set_cifscreds When debug logging is enabled… https://www.cve.org/CVERecord?id=CVE-2026-23303

    Post summary

    The Linux kernel CVE-2026-23303, which involved SMB client logging plaintext credentials, has been fixed, but no PoC, exploit, or detailed patch information is included.

    00010175
    56.8K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-23303 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-23303 #CVE-2026-23303 #CVE   #CyberSecurity #InfoSec https://t.co/SuakK1IUak

    Post summary

    The tweet announces CVE-2026‑23303, indicating an unknown risk level and unspecified affected products, while only linking to the NVD entry without providing further technical or remedial details.

    0000027
    123 followersView on X
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-23303 In the Linux kernel, the following vulnerability has been resolved: smb: client: Don't log plaintext credentials in cifs_set_cifscreds When debug logging is enabled… https://www.cve.org/CVERecord?id=CVE-2026-23303 ----- Traducción: CVE-2026-23303 En … http://infoflow.cloud`

    Post summary

    The post states that CVE‑2026‑23303, which caused plaintext SMB credentials to be logged by the Linux kernel, has been resolved, but provides no PoC, exploit, or active exploitation details.

    0000031
    61 followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel3.3--
OSlinuxlinux_kernel3.3--
OSlinuxlinux_kernel3.3--
OSlinuxlinux_kernel3.3--
OSlinuxlinux_kernel3.3--
OSlinuxlinux_kernel3.3--
OSlinuxlinux_kernel3.3--
OSlinuxlinux_kernel7.0--

Explore more