A Linux local privilege-escalation flaw dubbed CIFSwitch has been disclosed and assigned CVE-2026-46243, exposing systems that combine the kernel CIFS client with vulnerable cifs-utils configurations. Researcher Asim Manizada reported that an unprivileged user can forge a cifs.spnego key request, causing the root-run cifs.upcall helper to trust attacker-controlled fields such as identity and namespace targets. In affected versions, the helper can switch into attacker-controlled namespaces and perform NSS lookups before dropping privileges, allowing a malicious libnss_*.so.2 to execute as root. Reports say the underlying logic bug has existed since 2007, and public technical details and a proof of concept are now available.
The issue affects multiple distributions under common conditions, with several reported as exploitable by default, including Linux Mint, CentOS Stream 9, Rocky Linux 9, AlmaLinux 9, Kali Linux, and SLES 15, while Ubuntu, Debian, Oracle Linux, openSUSE Leap, and others can become vulnerable when cifs-utils is installed and user namespaces are enabled. Some newer platforms are partially protected by default SELinux or AppArmor policies, but vendors warned those controls are only defense in depth. Upstream fixed the bug in kernel commit 3da1fdf4efbc, which rejects userspace-originated cifs.spnego descriptions, and distributors have begun shipping patched kernels. Administrators are being urged to patch and reboot, or temporarily mitigate by removing cifs-utils, blacklisting the CIFS kernel module, overriding the cifs.spnego request-key rule, or disabling unprivileged user namespaces.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
A detailed classification of Linux distributions was published showing which systems were stock-exploitable, exploitable when cifs-utils was installed, blocked by default policy, or unaffected due to older cifs-utils versions. The matrix highlighted the role of SELinux, AppArmor, and namespace settings in exploitability.
AlmaLinux announced that AlmaLinux 8, 9, 10, and Kitten 10 were affected when cifs-utils was installed, and published patched kernel builds in its testing repository. It also recommended temporary mitigations such as removing cifs-utils, blocking the CIFS module, or redirecting the cifs.spnego request-key handler to /bin/false.
Manizada published full technical details and proof-of-concept exploit code showing how a low-privileged local user could abuse request_key("cifs.spnego", ...) and cifs.upcall behavior to gain root. The public write-up increased urgency for defenders to apply mitigations or patches.
After the embargo expired, Asim Manizada publicly disclosed the CIFSwitch local privilege escalation flaw affecting the Linux kernel CIFS client and cifs-utils. The disclosure described how forged cifs.spnego requests could lead to root code execution under common configurations.
A follow-up disclosure stated that the CIFSwitch local privilege escalation vulnerability had been assigned CVE-2026-46243. The update reiterated the exploit path through forged cifs.spnego requests and the affected conditions involving cifs-utils, the CIFS kernel module, and namespaces.
A kernel-side fix for the CIFSwitch issue, identified as commit 3da1fdf4efbc, was already public for over a week and queued for stable releases before the public disclosure. The fix rejects userspace-originated cifs.spnego descriptions that do not come from the CIFS client’s own credential path.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
8 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourcesecurityonline.info
Open sourcealmalinux.org
Open sourceopenwall.com
Open sourceseclists.org
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.