Описание
A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into entering a custom environment (namespace) containing a malicious NSS module. This forces the system to load the attacker's controlled NSS Module and configuration, allowing them to execute arbitrary commands as the root user, elevating their privileges and fully compromising the system.
Отчет
This vulnerability affects the cifs.upcall helper in cifs-utils. Red Hat Product Security has assessed this issue as an Important severity vulnerability. The flaw occurs because cifs.upcall performs user and group resolution operations after entering attacker-controlled namespaces but before fully dropping its elevated privileges. A local attacker may abuse this behavior to influence NSS module loading and execute arbitrary code with root privileges. Successful exploitation requires local access to the system and several environmental conditions, including registration of the cifs.spnego key type, the presence of the cifs-utils request-key rule, and the ability to create unprivileged user namespaces. However, once these conditions are met, exploitation may allow a local user to obtain root privileges.
Меры по смягчению последствий
Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | cifs-utils | Out of support scope | ||
| Red Hat Enterprise Linux 7 | cifs-utils | Affected | ||
| Red Hat Enterprise Linux 10 | cifs-utils | Fixed | RHSA-2026:32990 | 29.06.2026 |
| Red Hat Enterprise Linux 8 | cifs-utils | Fixed | RHSA-2026:39575 | 15.07.2026 |
| Red Hat Enterprise Linux 9 | cifs-utils | Fixed | RHSA-2026:39576 | 15.07.2026 |
| Red Hat Enterprise Linux 9 | cifs-utils | Fixed | RHSA-2026:39576 | 15.07.2026 |
| Red Hat OpenShift Container Platform 4.22 | rhcos-4.22.9.8.202607220526 | Fixed | RHSA-2026:44232 | 28.07.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.8 High
CVSS3
Связанные уязвимости
A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into entering a custom environment (namespace) containing a malicious NSS module. This forces the system to load the attacker's controlled NSS Module and configuration, allowing them to execute arbitrary commands as the root user, elevating their privileges and fully compromising the system.
A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into entering a custom environment (namespace) containing a malicious NSS module. This forces the system to load the attacker's controlled NSS Module and configuration, allowing them to execute arbitrary commands as the root user, elevating their privileges and fully compromising the system.
Cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall
A flaw was found in the cifs-utils package where the cifs.upcall helpe ...
EPSS
7.8 High
CVSS3