CVE-2025-2312

A flaw was found in cifs-utils. When trying to obtain Kerberos credentials, the cifs.upcall program from the cifs-utils package makes an upcall to the wrong namespace in containerized environments. This issue may lead to disclosing sensitive data from the host's Kerberos credentials cache.
Configurations

No configuration.

History

No history.

Information

Published : 2025-03-25 18:15

Updated : 2025-03-27 16:45


NVD link : CVE-2025-2312

Mitre link : CVE-2025-2312

CVE.ORG link : CVE-2025-2312


JSON object : View

Products Affected

No product.

CWE
CWE-488

Exposure of Data Element to Wrong Session