THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-64389 (HIGH 8.2) — In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate NTLMv2 response before updating session key ksmbd_auth_ntlmv2() derives the NTLMv2 session key into sess->sess_key before it verifies the NTLMv2 response. ksmbd_decode_ntlmssp_auth_blob() then c

[NVD] CVE-2026-64389 (HIGH 8.2) — In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate NTLMv2 response before updating session key ksmbd_auth_ntlmv2() derives the NTLMv2 session key into sess->sess_key before it verifies the NTLMv2 response. ksmbd_decode_ntlmssp_auth_blob() then c

lownvdPublished 2026-07-25

CVE-2026-64389 CVSS: 8.2 HIGH Published: 2026-07-25T10:17:22.227

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: validate NTLMv2 response before updating session key

ksmbd_auth_ntlmv2() derives the NTLMv2 session key into sess->sess_key before it verifies the NTLMv2 response. ksmbd_decode_ntlmssp_auth_blob() then continues into KEY_XCH even when ksmbd_auth_ntlmv2() fa

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-64389