CVE-2025-2312

Name
CVE-2025-2312
Description
A flaw was found in cifs-utils. When trying to obtain Kerberos credentials, the cifs.upcall program from the cifs-utils package makes an upcall to the wrong namespace in containerized environments. This issue may lead to disclosing sensitive data from the host's Kerberos credentials cache.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
patch https://git.samba.org/?p=cifs-utils.git;a=commit;h=89b679228cc1be9739d54203d28289b03352c174
patch https://web.git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/fs/smb?id=db363b0a1d9e6b9dc556296f1b1007aeb496a8cf

Match rules

CPE URI Source package Min version Max version
cifs-utils >= 0 < 7.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
cifs-utils edge-main 7.1-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable