First published: Tue Mar 25 2025(Updated: )
A flaw was found in cifs-utils. When trying to obtain Kerberos credentials, the cifs.upcall program from the cifs-utils package makes an upcall to the wrong namespace in containerized environments. This issue may lead to disclosing sensitive data from the host's Kerberos credentials cache.
Credit: 74b3a70d-cca6-4d34-9789-e83b222ae3be
Affected Software | Affected Version | How to fix |
---|---|---|
CIFS Utils |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2312 is classified as a medium severity vulnerability that could lead to the disclosure of sensitive Kerberos credentials.
To fix CVE-2025-2312, update to the latest version of the cifs-utils package that includes the patch for this vulnerability.
CVE-2025-2312 affects systems running cifs-utils, particularly in containerized environments where Kerberos credentials may be improperly handled.
CVE-2025-2312 may lead to the exposure of sensitive Kerberos credentials that could compromise system security.
CVE-2025-2312, while not extremely widespread, poses a significant risk in environments utilizing cifs-utils and Kerberos for authentication.