REDHAT-BUG-2489805: High severity cifs-utils cifs-utils vulnerability
The vulnerability affects cifs.upcall in cifs-utils. When processing a cifs.spnego key request, cifs.upcall may switch into attacker-controlled namespaces before fully dropping its root privileges. During this transition, the helper performs NSS lookups using getpwuid() while still retaining privileged kernel credentials. An attacker may create a controlled user and mount namespace containing a malicious NSS configuration and NSS module. By triggering a crafted cifs.spnego request through requestkey(), the attacker can cause cifs.upcall to load the malicious NSS module before privileges are fully dropped.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2489805?
The severity of REDHAT-BUG-2489805 is classified as high, with a score of 7.
How do I fix REDHAT-BUG-2489805?
To fix REDHAT-BUG-2489805, ensure that you update cifs-utils to the latest version that includes the security patches.
What components are affected by REDHAT-BUG-2489805?
The component affected by REDHAT-BUG-2489805 is cifs.upcall in the cifs-utils package.
What potential impact does REDHAT-BUG-2489805 have on systems?
REDHAT-BUG-2489805 can allow an attacker to operate within namespaces while the system still retains root privileges, leading to potential privilege escalation.
When was REDHAT-BUG-2489805 published?
REDHAT-BUG-2489805 was published on June 17, 2026.