cifs-utils-7.6-2.el9_8
エラータID: AXSA:2026-1506:05
The SMB/CIFS protocol is a standard file sharing protocol widely deployed on Microsoft Windows machines. The cifs-utils packages contain tools for mounting shares on Linux using the SMB/CIFS protocol. The tools in this package work in conjunction with support in the kernel to allow one to mount a SMB/CIFS share onto a client and use it as if it were a standard Linux file system.
Security Fix(es):
* cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall (CVE-2026-12505)
Bug Fix(es) and Enhancement(s):
* cifs-utils: regression with kerberos mount [rhel-9.8.z] (JIRA:RHEL-192982)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-12505
A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into entering a custom environment (namespace) containing a malicious NSS module. This forces the system to load the attacker's controlled NSS Module and configuration, allowing them to execute arbitrary commands as the root user, elevating their privileges and fully compromising the system.
Update packages.
A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into entering a custom environment (namespace) containing a malicious NSS module. This forces the system to load the attacker's controlled NSS Module and configuration, allowing them to execute arbitrary commands as the root user, elevating their privileges and fully compromising the system.
N/A
SRPMS
- cifs-utils-7.6-2.el9_8.src.rpm
MD5: bc1222a1808b3a9e4241b1db7929761f
SHA-256: 814e3ae30a5bc25ec6517a7f1b988787df04c38a24e687fe85257fc2206343e3
Size: 249.67 kB
Asianux Server 9 for x86_64
- cifs-utils-7.6-2.el9_8.x86_64.rpm
MD5: 9e5ba2c51ac1494700700e0a7b80db5a
SHA-256: c914190c6e78ddc6b5aa60c5566544c6d9c55de9fbabbdbf281732a341b223a7
Size: 119.08 kB - cifs-utils-devel-7.6-2.el9_8.i686.rpm
MD5: d8bc458f96bb5d666a76bcea9adaf22c
SHA-256: 89d11c9e549b8c9e960f581aeac533b640d17bcf5fdb4cb83b394126d4d89aa7
Size: 9.62 kB - cifs-utils-devel-7.6-2.el9_8.x86_64.rpm
MD5: 7ddece5bd8b0d96016f936db3febbb55
SHA-256: 0cd56ac2b4d60d92529771aa139fc5803ab557bf9c149b91445aed60e25d251a
Size: 9.59 kB - pam_cifscreds-7.6-2.el9_8.x86_64.rpm
MD5: 2f630d2bbf18a34890adb2c811dd8a99
SHA-256: 54c3c62f38958188a998b4587f726fa281971ba898e6a3d07e41dc4c47921e64
Size: 22.39 kB