
CVE-2025-2312 – cifs.upcall makes an upcall to the wrong namespace in containerized environments
https://notcve.org/view.php?id=CVE-2025-2312
25 Mar 2025 — A flaw was found in cifs-utils. When trying to obtain Kerberos credentials, the cifs.upcall program from the cifs-utils package makes an upcall to the wrong namespace in containerized environments. This issue may lead to disclosing sensitive data from the host's Kerberos credentials cache. Michael Randrianantenaina discovered that the Bluetooth driver in the Linux Kernel contained an improper access control vulnerability. A nearby attacker could use this to connect a rougue device and possibly execute arbit... • https://git.samba.org/?p=cifs-utils.git;a=commit;h=89b679228cc1be9739d54203d28289b03352c174 • CWE-488: Exposure of Data Element to Wrong Session •

CVE-2022-29869 – Gentoo Linux Security Advisory 202311-05
https://notcve.org/view.php?id=CVE-2022-29869
28 Apr 2022 — cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains = (equal sign) characters but is not a valid credentials file. cifs-utils versiones hasta 6.14, con registro detallado, puede causar un filtrado de información cuando un archivo contiene caracteres = (signo de igualdad) pero no es un archivo de credenciales válido Aurélien Aptel discovered that cifs-utils invoked a shell when requesting a password. In certain environments, a local attacker could possibly use th... • https://github.com/piastry/cifs-utils/commit/8acc963a2e7e9d63fe1f2e7f73f5a03f83d9c379 • CWE-532: Insertion of Sensitive Information into Log File •

CVE-2022-27239 – Gentoo Linux Security Advisory 202311-05
https://notcve.org/view.php?id=CVE-2022-27239
27 Apr 2022 — In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges. En cifs-utils versiones hasta 6.14, un desbordamiento del búfer en la región stack de la memoria cuando es analizado el argumento de línea de comandos mount.cifs ip= podría conllevar a que atacantes locales obtuvieran privilegios de root Aurélien Aptel discovered that cifs-utils invoked a shell when requesting a password. In certain environmen... • http://wiki.robotz.com/index.php/Linux_CIFS_Utils_and_Samba • CWE-787: Out-of-bounds Write •

CVE-2021-20208 – Ubuntu Security Notice USN-5459-1
https://notcve.org/view.php?id=CVE-2021-20208
19 Apr 2021 — A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vulnerability is to data confidentiality and integrity. Se encontró un fallo en cifs-utils en versiones anteriores a la 6.13. Cuando un usuario monta un sistema de archivos CIFS krb5 desde un contenedor, puede usar las credenciales de Kerberos del host. • https://bugzilla.redhat.com/show_bug.cgi?id=1921116 • CWE-266: Incorrect Privilege Assignment CWE-269: Improper Privilege Management •

CVE-2020-14342 – Ubuntu Security Notice USN-5459-1
https://notcve.org/view.php?id=CVE-2020-14342
09 Sep 2020 — It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject arbitrary commands. An attacker able to invoke mount.cifs with special permission, such as via sudo rules, could use this flaw to escalate their privileges. Se detectó que mount.cifs de cifs-utils estaba invocando un shell al requerir la contraseña de Samba, que podría ser usado para inyectar comandos arbitrarios. Un atacante capaz de invocar mount.cifs con un permiso especial... • http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00109.html • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVE-2014-2830 – Gentoo Linux Security Advisory 201612-08
https://notcve.org/view.php?id=CVE-2014-2830
30 Mar 2015 — Stack-based buffer overflow in cifskey.c or cifscreds.c in cifs-utils before 6.4, as used in pam_cifscreds, allows remote attackers to have unspecified impact via unknown vectors. Desbordamiento de buffer basado en pila en cifskey.c o cifscreds.c en cifs-utils anterior a 6.4, utilizado en pam_cifscreds, permite a atacantes remotos tener un impacto no especificado a través de vectores desconocidos. A vulnerability in LinuxCIFS utils' cifscreds PAM module might allow remote attackers to have an unspecified im... • http://advisories.mageia.org/MGASA-2014-0242.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2012-1586 – mount.cifs - 'chdir()' Arbitrary Root File Identification
https://notcve.org/view.php?id=CVE-2012-1586
27 Aug 2012 — mount.cifs in cifs-utils 2.6 allows local users to determine the existence of arbitrary files or directories via the file path in the second argument, which reveals their existence in an error message. mount.cifs en cifs-utils v2.6 permite a los usuarios locales determinar la existencia de ficheros o directorios arbitrarios a través de la ruta del archivo en el segundo argumento, que revela la existencia de un mensaje de error. • https://www.exploit-db.com/exploits/18783 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •