logo

CIFSwitch Local Root Exploit: Public Details and PoC Disclosed

ID: 39221828-ec98-5b94-89d2-b545c25a9191

STIX ID: report--39221828-ec98-5b94-89d2-b545c25a9191

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-28

Date Updated: 2026-05-28

Author: Ddos

...
...

The report describes a critical local root vulnerability (CIFSwitch) in Linux involving flawed validation in kernel key management and the cifs-utils privileged helper, allowing an unprivileged user to gain root by calling request_key with a forged CIFS SPNEGO description and leveraging namespace manipulation; a public proof-of-concept is available, multiple mainstream distributions are affected in default or common configurations, and mitigations (blocking the CIFS module, disabling unprivileged namespaces, overriding request-key rules) plus a queued kernel patch are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.