Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 14

Количество 14

ubuntu логотип

CVE-2026-12505

около 1 месяца назад

A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into entering a custom environment (namespace) containing a malicious NSS module. This forces the system to load the attacker's controlled NSS Module and configuration, allowing them to execute arbitrary commands as the root user, elevating their privileges and fully compromising the system.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2026-12505

около 2 месяцев назад

A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into entering a custom environment (namespace) containing a malicious NSS module. This forces the system to load the attacker's controlled NSS Module and configuration, allowing them to execute arbitrary commands as the root user, elevating their privileges and fully compromising the system.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-12505

около 1 месяца назад

A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into entering a custom environment (namespace) containing a malicious NSS module. This forces the system to load the attacker's controlled NSS Module and configuration, allowing them to execute arbitrary commands as the root user, elevating their privileges and fully compromising the system.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2026-12505

около 1 месяца назад

Cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2026-12505

около 1 месяца назад

A flaw was found in the cifs-utils package where the cifs.upcall helpe ...

CVSS3: 7.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2700-1

около 1 месяца назад

Security update for cifs-utils

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2699-1

около 1 месяца назад

Security update for cifs-utils

EPSS: Низкий
rocky логотип

RLSA-2026:39576

16 дней назад

Important: cifs-utils security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2026:39575

8 дней назад

Important: cifs-utils security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2026:32990

26 дней назад

Important: cifs-utils security update

EPSS: Низкий
github логотип

GHSA-58j9-p7xf-pjx7

около 1 месяца назад

A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into entering a custom environment (namespace) containing a malicious NSS module. This forces the system to load the attacker's controlled NSS Module and configuration, allowing them to execute arbitrary commands as the root user, elevating their privileges and fully compromising the system.

CVSS3: 7.8
EPSS: Низкий
oracle-oval логотип

ELSA-2026-39576

17 дней назад

ELSA-2026-39576: cifs-utils security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-39575

17 дней назад

ELSA-2026-39575: cifs-utils security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-32990

11 дней назад

ELSA-2026-32990: cifs-utils security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-12505

A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into entering a custom environment (namespace) containing a malicious NSS module. This forces the system to load the attacker's controlled NSS Module and configuration, allowing them to execute arbitrary commands as the root user, elevating their privileges and fully compromising the system.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-12505

A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into entering a custom environment (namespace) containing a malicious NSS module. This forces the system to load the attacker's controlled NSS Module and configuration, allowing them to execute arbitrary commands as the root user, elevating their privileges and fully compromising the system.

CVSS3: 7.8
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-12505

A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into entering a custom environment (namespace) containing a malicious NSS module. This forces the system to load the attacker's controlled NSS Module and configuration, allowing them to execute arbitrary commands as the root user, elevating their privileges and fully compromising the system.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
msrc логотип
CVE-2026-12505

Cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-12505

A flaw was found in the cifs-utils package where the cifs.upcall helpe ...

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2700-1

Security update for cifs-utils

0%
Низкий
около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2699-1

Security update for cifs-utils

0%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:39576

Important: cifs-utils security, bug fix, and enhancement update

0%
Низкий
16 дней назад
rocky логотип
RLSA-2026:39575

Important: cifs-utils security, bug fix, and enhancement update

0%
Низкий
8 дней назад
rocky логотип
RLSA-2026:32990

Important: cifs-utils security update

0%
Низкий
26 дней назад
github логотип
GHSA-58j9-p7xf-pjx7

A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into entering a custom environment (namespace) containing a malicious NSS module. This forces the system to load the attacker's controlled NSS Module and configuration, allowing them to execute arbitrary commands as the root user, elevating their privileges and fully compromising the system.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
oracle-oval логотип
ELSA-2026-39576

ELSA-2026-39576: cifs-utils security, bug fix, and enhancement update (IMPORTANT)

17 дней назад
oracle-oval логотип
ELSA-2026-39575

ELSA-2026-39575: cifs-utils security, bug fix, and enhancement update (IMPORTANT)

17 дней назад
oracle-oval логотип
ELSA-2026-32990

ELSA-2026-32990: cifs-utils security update (IMPORTANT)

11 дней назад

Уязвимостей на страницу