A newly disclosed Linux local privilege escalation vulnerability dubbed CIFSwitch allows a low-privileged user to gain root by exploiting a logic flaw between the kernel CIFS client and the userspace cifs-utils package. Researcher Asim Manizada reported that the kernel does not properly verify whether cifs.spnego key descriptions actually originate from the CIFS subsystem, allowing forged request_key() calls to reach the root-privileged cifs.upcall helper with attacker-controlled input. By manipulating fields including pid and upcall_target, an attacker can steer cifs.upcall into attacker-controlled namespaces and abuse NSS resolution to load a malicious libnss module, resulting in arbitrary code execution as root.
The bug reportedly dates back to 2007 and affects systems running vulnerable kernels together with certain cifs-utils versions, with exploitation depending on conditions such as unprivileged user namespaces and permissive LSM policies. Upstream kernel patches are available, and defenders are being urged to apply fixes quickly while considering interim mitigations such as disabling CIFS where it is not needed, removing cifs-utils, tightening request-key rules, and restricting unprivileged user namespaces. The disclosure follows broader scrutiny of Linux local privilege escalation handling after debate around CopyFail (CVE-2026-31431), where oss-security participants criticized sparse CVE detail, limited early warning, and the difficulty of prioritizing kernel flaws likely to become operationally significant.

Get the actors, campaigns, and ATT&CK mapping behind it.
8 events from the most recent confirmed update back to the earliest known activity.
Coverage of CIFSwitch said the flaw dates back to 2007, affects vulnerable kernels with certain cifs-utils versions, and that upstream kernel patches were available along with mitigation advice such as restricting unprivileged user namespaces and tightening request-key rules.
Asim Manizada published CIFSwitch, describing a Linux local privilege escalation caused by a logic flaw between the kernel CIFS client and cifs-utils that can let a low-privileged user gain root under certain conditions.
Emily Shepherd and others used the CVE-2026-31431 case on oss-security to argue that the Linux kernel disclosure workflow is opaque, places too much burden on reporters, and produces CVE descriptions that lack useful threat and mitigation detail.
Responding on oss-security, Greg Kroah-Hartman said the kernel security team focuses on triaging reports, involving maintainers, and getting fixes merged quickly, and that it does not make vulnerability announcements.
An oss-security thread stated that xint had supplied the Linux kernel security team with a fully working exploit when reporting CVE-2026-31431, and referenced public materials including the copy.fail site, a detailed blog post, and a Python proof of concept.
Participants on oss-security discussed operational mitigations for CVE-2026-31431, noting that when vulnerable functionality is modular it may be disabled or unloaded, while kernels with the code built in may require a boot parameter change and reboot.
An oss-security discussion covered how CVE-2026-31431 was prioritized, with Greg Kroah-Hartman saying users should update to the latest release and that the CVE team did not know exploitation was imminent or provide advance notice to selected parties such as distros.
In an oss-security mailing list message, Greg Kroah-Hartman said the CVE entry for CVE-2026-31431 (CopyFail) already included a severity score and advised supported users to ask their Linux distribution vendor about handling under support contracts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
12 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceheyitsas.im
Open sourceopenwall.com
Open sourceopenwall.com
Open sourceopenwall.com
Open sourceopenwall.com
Open sourceopenwall.com
Open sourceopenwall.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.