logo

CIFSwitch, a Linux Root Bug Hidden in Plain Sight for 19 Years

ID: 19da3b40-d274-5980-bd78-5075c073adb5

STIX ID: report--19da3b40-d274-5980-bd78-5075c073adb5

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-06-01

Date Updated: 2026-06-01

Author: Pierluigi Paganini

...
...

CIFSwitch is a 19-year-old Linux logic vulnerability in the CIFS client and cifs-utils helper that lets an attacker fabricate a cifs.spnego key and cause the root-run cifs.upcall to load attacker-controlled NSS libraries before dropping privileges, enabling local root. A public PoC exists, a kernel patch has been landed upstream, and exploitation depends on a vulnerable kernel, cifs-utils, and permissive user namespaces or MAC policies; removal of cifs-utils or blacklisting CIFS mitigates exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.