Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 14

Количество 14

github логотип

GHSA-58j9-p7xf-pjx7

3 месяца назад

A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into entering a custom environment (namespace) containing a malicious NSS module. This forces the system to load the attacker's controlled NSS Module and configuration, allowing them to execute arbitrary commands as the root user, elevating their privileges and fully compromising the system.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2026-12505

3 месяца назад

A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into entering a custom environment (namespace) containing a malicious NSS module. This forces the system to load the attacker's controlled NSS Module and configuration, allowing them to execute arbitrary commands as the root user, elevating their privileges and fully compromising the system.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2026-12505

3 месяца назад

A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into entering a custom environment (namespace) containing a malicious NSS module. This forces the system to load the attacker's controlled NSS Module and configuration, allowing them to execute arbitrary commands as the root user, elevating their privileges and fully compromising the system.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-12505

3 месяца назад

A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into entering a custom environment (namespace) containing a malicious NSS module. This forces the system to load the attacker's controlled NSS Module and configuration, allowing them to execute arbitrary commands as the root user, elevating their privileges and fully compromising the system.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2026-12505

3 месяца назад

Cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2026-12505

3 месяца назад

A flaw was found in the cifs-utils package where the cifs.upcall helpe ...

CVSS3: 7.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2700-1

3 месяца назад

Security update for cifs-utils

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2699-1

3 месяца назад

Security update for cifs-utils

EPSS: Низкий
rocky логотип

RLSA-2026:39576

2 месяца назад

Important: cifs-utils security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2026:39575

2 месяца назад

Important: cifs-utils security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2026:32990

3 месяца назад

Important: cifs-utils security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-39576

2 месяца назад

ELSA-2026-39576: cifs-utils security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-39575

2 месяца назад

ELSA-2026-39575: cifs-utils security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-32990

2 месяца назад

ELSA-2026-32990: cifs-utils security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-58j9-p7xf-pjx7

A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into entering a custom environment (namespace) containing a malicious NSS module. This forces the system to load the attacker's controlled NSS Module and configuration, allowing them to execute arbitrary commands as the root user, elevating their privileges and fully compromising the system.

CVSS3: 7.8
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-12505

A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into entering a custom environment (namespace) containing a malicious NSS module. This forces the system to load the attacker's controlled NSS Module and configuration, allowing them to execute arbitrary commands as the root user, elevating their privileges and fully compromising the system.

CVSS3: 7.8
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-12505

A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into entering a custom environment (namespace) containing a malicious NSS module. This forces the system to load the attacker's controlled NSS Module and configuration, allowing them to execute arbitrary commands as the root user, elevating their privileges and fully compromising the system.

CVSS3: 7.8
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-12505

A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into entering a custom environment (namespace) containing a malicious NSS module. This forces the system to load the attacker's controlled NSS Module and configuration, allowing them to execute arbitrary commands as the root user, elevating their privileges and fully compromising the system.

CVSS3: 7.8
0%
Низкий
3 месяца назад
msrc логотип
CVE-2026-12505

Cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall

CVSS3: 7.8
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-12505

A flaw was found in the cifs-utils package where the cifs.upcall helpe ...

CVSS3: 7.8
0%
Низкий
3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2700-1

Security update for cifs-utils

0%
Низкий
3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2699-1

Security update for cifs-utils

0%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:39576

Important: cifs-utils security, bug fix, and enhancement update

0%
Низкий
2 месяца назад
rocky логотип
RLSA-2026:39575

Important: cifs-utils security, bug fix, and enhancement update

0%
Низкий
2 месяца назад
rocky логотип
RLSA-2026:32990

Important: cifs-utils security update

0%
Низкий
3 месяца назад
oracle-oval логотип
ELSA-2026-39576

ELSA-2026-39576: cifs-utils security, bug fix, and enhancement update (IMPORTANT)

0%
Низкий
2 месяца назад
oracle-oval логотип
ELSA-2026-39575

ELSA-2026-39575: cifs-utils security, bug fix, and enhancement update (IMPORTANT)

0%
Низкий
2 месяца назад
oracle-oval логотип
ELSA-2026-32990

ELSA-2026-32990: cifs-utils security update (IMPORTANT)

0%
Низкий
2 месяца назад

Уязвимостей на страницу