logo

New CIFSwitch Linux flaw gives root on multiple distributions

ID: 81ae20a2-68c4-5887-91f5-e54615a28d6c

STIX ID: report--81ae20a2-68c4-5887-91f5-e54615a28d6c

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-05-30

Date Updated: 2026-05-30

Author: Bill Toulas

...
...

A local privilege escalation vulnerability called CIFSwitch in the Linux kernel's CIFS subsystem allows unprivileged users to forge cifs.spnego key requests and trick the root-privileged cifs.upcall helper into loading attacker-controlled NSS modules, resulting in root code execution; the flaw affects multiple Linux distributions under specific configurations, an upstream kernel patch and mitigations are available, and a proof-of-concept exploit has been published.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.