A flaw was found in cifs-utils. When trying to obtain Kerberos credentials, the cifs.upcall program from the cifs-utils package makes an upcall to the wrong namespace in containerized environments. This issue may lead to disclosing sensitive data from the host's Kerberos credentials cache.
History

Tue, 25 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Mar 2025 18:15:00 +0000

Type Values Removed Values Added
Title cifs-utils: kernel: cifs-utils: cifs.upcall makes an upcall to the wrong namespace in containerized environments cifs.upcall makes an upcall to the wrong namespace in containerized environments
References

Tue, 18 Mar 2025 02:30:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. A flaw was found in cifs-utils. When trying to obtain Kerberos credentials, the cifs.upcall program from the cifs-utils package makes an upcall to the wrong namespace in containerized environments. This issue may lead to disclosing sensitive data from the host's Kerberos credentials cache.

Sat, 15 Mar 2025 02:45:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title cifs-utils: kernel: cifs-utils: cifs.upcall makes an upcall to the wrong namespace in containerized environments
Weaknesses CWE-488
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N'}

threat_severity

Moderate


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat-cnalr

Published:

Updated: 2025-03-25T18:23:15.943Z

Reserved: 2025-03-14T14:44:33.471Z

Link: CVE-2025-2312

cve-icon Vulnrichment

Updated: 2025-03-25T18:23:07.319Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-03-25T18:15:34.987

Modified: 2025-03-27T16:45:46.410

Link: CVE-2025-2312

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-11-11T00:00:00Z

Links: CVE-2025-2312 - Bugzilla