PT-2026-50619 · Unknown+3 · Cifs-Utils+3

CVE-2026-12505

·

Published

2026-06-18

·

Updated

2026-08-31

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions cifs-utils (affected versions not specified)
Description A flaw exists in the cifs.upcall helper that fails to securely drop root privileges before performing user information lookups within a user-controlled environment. A local, low-privileged attacker can use a crafted request key payload to trick the root-owned helper into entering a custom namespace containing a malicious Name Service Switch (NSS) module. This forces the system to load the attacker's controlled NSS module and configuration, enabling the execution of arbitrary commands as the root user and resulting in full system compromise.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:39575
ALSA-2026:39576
AZL-91131
CVE-2026-12505
ECHO-384F-89A4-EA70
OESA-2026-3028
OESA-2026-3029
OESA-2026-3030
OESA-2026-3031
OESA-2026-3032
RHSA-2026:32990
RHSA-2026:39575
RHSA-2026:39576
SUSE-SU-2026:22888-1
SUSE-SU-2026:2699-1
SUSE-SU-2026:2700-1
USN-8496-1
USN-8496-2
USN-8496-3

Affected Products

Linuxmint
Rocky Linux
Ubuntu
Cifs-Utils