We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-2312

cifs.upcall makes an upcall to the wrong namespace in containerized environments



Description

A flaw was found in cifs-utils. When trying to obtain Kerberos credentials, the cifs.upcall program from the cifs-utils package makes an upcall to the wrong namespace in containerized environments. This issue may lead to disclosing sensitive data from the host's Kerberos credentials cache.

Reserved 2025-03-14 | Published 2025-03-25 | Updated 2025-03-25 | Assigner redhat-cnalr


MEDIUM: 5.9CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N

Problem types

CWE-488

Product status

Default status
unaffected

Any version before 7.2
affected

References

git.samba.org/...;h=89b679228cc1be9739d54203d28289b03352c174 patch

web.git.kernel.org/...363b0a1d9e6b9dc556296f1b1007aeb496a8cf patch

cve.org (CVE-2025-2312)

nvd.nist.gov (CVE-2025-2312)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-2312

Support options

Helpdesk Chat, Email, Knowledgebase