A local privilege escalation flaw in Linux systems using CIFS/Kerberos authentication and cifs-utils can allow an unprivileged user to execute code as root by abusing the cifs.spnego request-key mechanism. The issue arises because the cifs.upcall helper may be invoked with elevated privileges and can be influenced through Name Service Switch (NSS) resolution, enabling an attacker to load a malicious libnss_*.so.2 library under certain namespace and configuration conditions.
Testing cited in the reports found many Linux distributions vulnerable, while some were protected by default through SELinux or AppArmor policies that blocked exploitation despite shipping affected behavior. Recommended mitigations included disabling the CIFS kernel module, turning off unprivileged user namespaces, or overriding the cifs.spnego request-key rule so requests are denied instead of passed to the helper; the reports also noted broad disclosure activity across distributions and a large number of related vulnerability reports awaiting review.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
A Linux kernel stable-tree patch hardened the CIFS SMB client by rejecting userspace-created cifs.spnego key descriptions unless they originate from the private spnego_cred context. The change was intended to stop forged authority-bearing fields from being passed to cifs.upcall as if they were kernel-originating data.
A write-up disclosed a local privilege escalation vulnerability involving the Linux CIFS/Kerberos authentication path, where the cifs.spnego request-key handler can invoke cifs.upcall as root and be abused via NSS to load attacker-controlled libraries. The disclosure noted many Linux distributions were affected or exploitable depending on namespace availability and SELinux/AppArmor protections, and suggested mitigations such as disabling the CIFS module, disabling unprivileged user namespaces, or overriding the cifs.spnego rule.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
git.kernel.org
Open sourceopennet.me
Open sourceopennet.ru
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.