THREAT OPS › Threat News › [NVD] CVE-2026-64389 (HIGH 8.2) — In the Linux kernel, the following vulnerability has been resolved:
ksmbd: validate NTLMv2 response before updating session key
ksmbd_auth_ntlmv2() derives the NTLMv2 session key into
sess->sess_key before it verifies the NTLMv2 response.
ksmbd_decode_ntlmssp_auth_blob() then c
[NVD] CVE-2026-64389 (HIGH 8.2) — In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate NTLMv2 response before updating session key ksmbd_auth_ntlmv2() derives the NTLMv2 session key into sess->sess_key before it verifies the NTLMv2 response. ksmbd_decode_ntlmssp_auth_blob() then c
CVE-2026-64389 CVSS: 8.2 HIGH Published: 2026-07-25T10:17:22.227
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: validate NTLMv2 response before updating session key
ksmbd_auth_ntlmv2() derives the NTLMv2 session key into sess->sess_key before it verifies the NTLMv2 response. ksmbd_decode_ntlmssp_auth_blob() then continues into KEY_XCH even when ksmbd_auth_ntlmv2() fa
Indicators of compromise
- CVE-2026-64389cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-64389