OESA-2026-3029

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-3029
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-3029.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-3029
Upstream
  • CVE-2026-12505
Published
2026-07-19T03:48:09Z
Modified
2026-07-19T04:00:18.329723988Z
Summary
cifs-utils security update
Details

The in-kernel CIFS filesystem is generally the preferred method for mounting SMB/CIFS shares on Linux.

Security Fix(es):

A flaw was found in cifs-utils. When trying to obtain Kerberos credentials, the cifs.upcall program from the cifs-utils package makes an upcall to the wrong namespace in containerized environments. This issue may lead to disclosing sensitive data from the host's Kerberos credentials cache.(CVE-2025-2312)

A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into entering a custom environment (namespace) containing a malicious NSS module. This forces the system to load the attacker's controlled NSS Module and configuration, allowing them to execute arbitrary commands as the root user, elevating their privileges and fully compromising the system.(CVE-2026-12505)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:20.03-LTS-SP4 / cifs-utils

Package

Name
cifs-utils
Purl
pkg:rpm/openEuler/cifs-utils&distro=openEuler-20.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.10-9.oe2003sp4

Ecosystem specific

{
    "aarch64": [
        "cifs-utils-6.10-9.oe2003sp4.aarch64.rpm",
        "cifs-utils-debuginfo-6.10-9.oe2003sp4.aarch64.rpm",
        "cifs-utils-debugsource-6.10-9.oe2003sp4.aarch64.rpm",
        "cifs-utils-devel-6.10-9.oe2003sp4.aarch64.rpm",
        "cifs-utils-help-6.10-9.oe2003sp4.aarch64.rpm"
    ],
    "x86_64": [
        "cifs-utils-6.10-9.oe2003sp4.x86_64.rpm",
        "cifs-utils-debuginfo-6.10-9.oe2003sp4.x86_64.rpm",
        "cifs-utils-debugsource-6.10-9.oe2003sp4.x86_64.rpm",
        "cifs-utils-devel-6.10-9.oe2003sp4.x86_64.rpm",
        "cifs-utils-help-6.10-9.oe2003sp4.x86_64.rpm"
    ],
    "src": [
        "cifs-utils-6.10-9.oe2003sp4.src.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-3029.json"