CVE-2025-2312

A flaw was found in cifs-utils. When trying to obtain Kerberos credentials, the cifs.upcall program from the cifs-utils package makes an upcall to the wrong namespace in containerized environments. This issue may lead to disclosing sensitive data from the host's Kerberos credentials cache.
Configurations

No configuration.

History

27 Mar 2025, 16:45

Type Values Removed Values Added
Summary
  • (es) Se detectó una falla en cifs-utils. Al intentar obtener credenciales Kerberos, el programa cifs.upcall del paquete cifs-utils realiza una llamada ascendente al espacio de nombres incorrecto en entornos contenedorizados. Este problema puede provocar la divulgación de datos confidenciales de la caché de credenciales Kerberos del host.

25 Mar 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-25 18:15

Updated : 2025-03-27 16:45


NVD link : CVE-2025-2312

Mitre link : CVE-2025-2312

CVE.ORG link : CVE-2025-2312


JSON object : View

Products Affected

No product.

CWE
CWE-488

Exposure of Data Element to Wrong Session