Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-12505

Опубликовано: 16 июн. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into entering a custom environment (namespace) containing a malicious NSS module. This forces the system to load the attacker's controlled NSS Module and configuration, allowing them to execute arbitrary commands as the root user, elevating their privileges and fully compromising the system.

Отчет

This vulnerability affects the cifs.upcall helper in cifs-utils. Red Hat Product Security has assessed this issue as an Important severity vulnerability. The flaw occurs because cifs.upcall performs user and group resolution operations after entering attacker-controlled namespaces but before fully dropping its elevated privileges. A local attacker may abuse this behavior to influence NSS module loading and execute arbitrary code with root privileges. Successful exploitation requires local access to the system and several environmental conditions, including registration of the cifs.spnego key type, the presence of the cifs-utils request-key rule, and the ability to create unprivileged user namespaces. However, once these conditions are met, exploitation may allow a local user to obtain root privileges.

The issue has been fixed by upstream in cifs-utils v7.6

Меры по смягчению последствий

Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6cifs-utilsOut of support scope
Red Hat Enterprise Linux 7cifs-utilsAffected
Red Hat Enterprise Linux 10cifs-utilsFixedRHSA-2026:3299029.06.2026
Red Hat Enterprise Linux 8cifs-utilsFixedRHSA-2026:3957515.07.2026
Red Hat Enterprise Linux 9cifs-utilsFixedRHSA-2026:3957615.07.2026
Red Hat Enterprise Linux 9cifs-utilsFixedRHSA-2026:3957615.07.2026
Red Hat OpenShift Container Platform 4.22rhcos-4.22.9.8.202607220526FixedRHSA-2026:4423228.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-250
https://bugzilla.redhat.com/show_bug.cgi?id=2489805cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall

EPSS

Процентиль: 5%
0.00157
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 1 месяца назад

A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into entering a custom environment (namespace) containing a malicious NSS module. This forces the system to load the attacker's controlled NSS Module and configuration, allowing them to execute arbitrary commands as the root user, elevating their privileges and fully compromising the system.

CVSS3: 7.8
nvd
около 1 месяца назад

A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into entering a custom environment (namespace) containing a malicious NSS module. This forces the system to load the attacker's controlled NSS Module and configuration, allowing them to execute arbitrary commands as the root user, elevating their privileges and fully compromising the system.

CVSS3: 7.8
msrc
около 1 месяца назад

Cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall

CVSS3: 7.8
debian
около 1 месяца назад

A flaw was found in the cifs-utils package where the cifs.upcall helpe ...

suse-cvrf
около 1 месяца назад

Security update for cifs-utils

EPSS

Процентиль: 5%
0.00157
Низкий

7.8 High

CVSS3