#1140422 cifs-utils: CVE-2026-12505

Package:
src:cifs-utils
Source:
src:cifs-utils
Submitter:
Salvatore Bonaccorso
Date:
2026-09-26 13:37:03 UTC
Severity:
normal
Tags:
#1140422#5
Date:
2026-06-20 05:42:54 UTC
From:
To:
Hi,

The following vulnerability was published for cifs-utils.

CVE-2026-12505[0]:
| A flaw was found in the cifs-utils package where the cifs.upcall
| helper fails to securely drop its root privileges before looking up
| user information inside a user-controlled environment. A local, low
| privileged attacker can exploit this by using a crafted request_key
| payload to trick the root-owned helper into entering a custom
| environment (namespace) containing a malicious NSS module. This
| forces the system to load the attacker's controlled NSS Module and
| configuration, allowing them to execute arbitrary commands as the
| root user, elevating their privileges and fully compromising the
| system.

If I'm not completely wrong this helped to exploit CVE-2026-46243
without the kernel side fix.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-12505
https://www.cve.org/CVERecord?id=CVE-2026-12505
[1] https://bugzilla.redhat.com/show_bug.cgi?id=2489805
[2] https://git.samba.org/?p=cifs-utils.git;a=commit;h=972c5b5ff95e3e812bc8daa72d0383654ab0dba7

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1140422#10
Date:
2026-09-26 13:35:48 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
cifs-utils, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1140422@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Michael Tokarev <mjt@tls.msk.ru> (supplier of updated cifs-utils package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 26 Sep 2026 16:22:18 +0300
Source: cifs-utils
Architecture: source
Version: 2:7.8-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Samba Maintainers <pkg-samba-maint@lists.alioth.debian.org>
Changed-By: Michael Tokarev <mjt@tls.msk.ru>
Closes: 1140422
Changes:
 cifs-utils (2:7.8-1) unstable; urgency=medium
 .
   * new upstream release (7.8)
     Closes: #1140422, CVE-2026-12505
   * d/control: Remove Priority: optional and Rules-Requires-Root: no
   * d/control: Standards-Version: 4.7.4 (no changes)
Checksums-Sha1:
 89eda021ea1576f1a4efe69437ccca0df63faabb 2482 cifs-utils_7.8-1.dsc
 fb8b683e45d5a7168c7dacc539ff4c556e4a1430 427300 cifs-utils_7.8.orig.tar.bz2
 2cdb482c20634131ccbff95a0f08569ed3151a79 833 cifs-utils_7.8.orig.tar.bz2.asc
 92daa6b8c81e9230a8676fb3382d675d2125a61b 10392 cifs-utils_7.8-1.debian.tar.xz
 880d352be31b453237a4f2cbaa4d5c9779bf0ba5 6299 cifs-utils_7.8-1_source.buildinfo
Checksums-Sha256:
 1b9c7973d16ac314d8a4d02a1c757986baf1eb9364366130e010274439bcfb53 2482 cifs-utils_7.8-1.dsc
 b5321d3ff848d361c129aeec4ec8431642582b7036cb8a2a403667d5909d4172 427300 cifs-utils_7.8.orig.tar.bz2
 2c34ca4f5e9a0208d8ffc06ed9b8474696dcfa782be6db2a5c5767ef9e017620 833 cifs-utils_7.8.orig.tar.bz2.asc
 fe8c441c146ae4574ca764a9a0f5b5ec1262cfe2577c4230344a4ab9b81e22ed 10392 cifs-utils_7.8-1.debian.tar.xz
 2f5bc275c67d1931c735e39b52e702050013bfdfbb83b3302885fd0e56c73269 6299 cifs-utils_7.8-1_source.buildinfo
Files:
 7456f477fc9be5fc27c4164c141595c7 2482 otherosfs optional cifs-utils_7.8-1.dsc
 a8f1b4fc9688a459f1570988116a3c3c 427300 otherosfs optional cifs-utils_7.8.orig.tar.bz2
 d88f33000eea1798c5b7039b644f789a 833 otherosfs optional cifs-utils_7.8.orig.tar.bz2.asc
 3ad7ade30e71979800cd6eb5f9e1474e 10392 otherosfs optional cifs-utils_7.8-1.debian.tar.xz
 4291d6903aa5f808bd591de020106c18 6299 otherosfs optional cifs-utils_7.8-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEZKoqtTHVaQM2a/75gqpKJDselHgFAmq3x2QACgkQgqpKJDse
lHgdexAAyLi8UUhW1UDMhKE0HWLAsdxxfLNHFLAwpktWgFr3T+GPQF6KFdCZJNTl
ruJ5bCW/xZvl6RUgy8N6s7RRtN+KjUQynqvv+AeqJiuEmOvsYMfhyHbcDCsrNFXY
8IQBgc4BkjhZsPluVp8RPeDw2PCbxloxVn73ui1Fvl+hBVWGe+n66ds21oAD2dug
RAUB76mlbiu20Zp0n90l/hSeEz6admBsEaKfpL4NKi3Mxpu7T4whMYT2v95PmEd3
5qqf6ACf5WDViJcNz2GtDp2Daxca1dXQJEB1gHpqVMEhhhyBHkXp3aamnjO5kBY6
99REkfdfKwStPrdp/DHEYsf35dERUpg+vAEgpLONvlCB9N5Ad72OWPhJ57CnlHoM
sMxGcpLSIhbJ5iBYSrV0SEcFJjuJIEM6Q87tsjZ6y1Uqfg1g3z2ShHhE6t8NWUW2
K5xL7GZ4tLesDAfRmbt4dSHS/O9hRIUnUh5is8wqWd88Y65W4qp3jh81KcpAG68U
XYSMeE0KsgaJppLKt8zUr2Z5M8EL+WetyGQWbDlFZWVywIfsvkGMdIc0jBWqte5/
aaK/TVUrg8fhio222u9SGStiLrERgGfhpVw3xfhVgARSsXDETCIHKvc1qxWlZP0A
QW+ff5HjvrCuAfpAFb+VvC5tpBwlCDHMl+uYGw5CyyWtQBLzSyo=
=IdpM
-----END PGP SIGNATURE-----