CVE-2026-12505

EUVD-2026-37834
A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into entering a custom environment (namespace) containing a malicious NSS module. This forces the system to load the attacker's controlled NSS Module and configuration, allowing them to execute arbitrary commands as the root user, elevating their privileges and fully compromising the system.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 5%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat Enterprise Linux 10
0:7.6-1.el10_2 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8
0:7.0-5.el8_10 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9
0:7.6-2.el9_8 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.22
4.22.9.8.202607220526-0 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
cifs-utils
bookworm
postponed
bullseye
postponed
bullseye (security)
vulnerable
forky
vulnerable
sid
vulnerable
trixie
no-dsa
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
cifs-utils
suse enterprise desktop 15 SP7
6.15-150400.3.21.1
fixed
suse enterprise sap 15 SP4
6.15-150400.3.21.1
fixed
suse enterprise sap 15 SP5
6.15-150400.3.21.1
fixed
suse enterprise sap 15 SP6
6.15-150400.3.21.1
fixed
suse enterprise sap 15 SP7
6.15-150400.3.21.1
fixed
suse enterprise server 12 SP5
6.9-13.26.1
fixed
suse enterprise server 15 SP4
6.15-150400.3.21.1
fixed
suse enterprise server 15 SP5
6.15-150400.3.21.1
fixed
suse enterprise server 15 SP6
6.15-150400.3.21.1
fixed
suse enterprise server 15 SP7
6.15-150400.3.21.1
fixed
cifs-utils-devel
suse enterprise desktop 15 SP7
6.15-150400.3.21.1
fixed
suse enterprise sap 15 SP4
6.15-150400.3.21.1
fixed
suse enterprise sap 15 SP5
6.15-150400.3.21.1
fixed
suse enterprise sap 15 SP6
6.15-150400.3.21.1
fixed
suse enterprise sap 15 SP7
6.15-150400.3.21.1
fixed
suse enterprise server 12 SP5
6.9-13.26.1
fixed
suse enterprise server 15 SP4
6.15-150400.3.21.1
fixed
suse enterprise server 15 SP5
6.15-150400.3.21.1
fixed
suse enterprise server 15 SP6
6.15-150400.3.21.1
fixed
suse enterprise server 15 SP7
6.15-150400.3.21.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
cifs-utils
RHEL 8
0:7.0-5.el8_10
fixed
RHEL 9
0:7.6-2.el9_8
fixed
cifs-utils-devel
RHEL 8
0:7.0-5.el8_10
fixed
RHEL 9
0:7.6-2.el9_8
fixed
pam
RHEL 8
0:7.0-5.el8_10
fixed
RHEL 9
0:7.6-2.el9_8
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
cifs-utils
Azure Linux 3.0
0:7.6-1.azl3
fixed