CIFSwitch Local Root Exploit: Public Details and PoC Disclosed
ID: 39221828-ec98-5b94-89d2-b545c25a9191
STIX ID: report--39221828-ec98-5b94-89d2-b545c25a9191
Feed Name: securityonline.info
The report describes a critical local root vulnerability (CIFSwitch) in Linux involving flawed validation in kernel key management and the cifs-utils privileged helper, allowing an unprivileged user to gain root by calling request_key with a forged CIFS SPNEGO description and leveraging namespace manipulation; a public proof-of-concept is available, multiple mainstream distributions are affected in default or common configurations, and mitigations (blocking the CIFS module, disabling unprivileged namespaces, overriding request-key rules) plus a queued kernel patch are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
