REDHAT-BUG-2352604: Medium severity cifs utils vulnerability
While trying to get Kerberos credentials, cifs.upcall program from the cifs-utils package makes an upcall to the wrong namespace in containerized environments. This may lead to a disclosure of sensitive data from the host's Kerberos credentials cache.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2352604?
The severity of REDHAT-BUG-2352604 is considered high due to the risk of sensitive data exposure.
How do I fix REDHAT-BUG-2352604?
To mitigate REDHAT-BUG-2352604, ensure that your cifs-utils package is updated to the latest version with the necessary patches applied.
Which systems are affected by REDHAT-BUG-2352604?
REDHAT-BUG-2352604 affects containerized environments utilizing the cifs-utils package.
What type of data is at risk due to REDHAT-BUG-2352604?
The vulnerability in REDHAT-BUG-2352604 may lead to the disclosure of sensitive Kerberos credentials from the host.
Is there a workaround for REDHAT-BUG-2352604?
A possible workaround for REDHAT-BUG-2352604 is to restrict the use of cifs-utils in non-isolated environments until the issue is resolved.