Bleepingcomputer CIFSwitch Vulnerability in Linux Allows Root Access via CIFS Exploit
Article Content
- •CIFSwitch vulnerability allows root access via forged CIFS authentication requests.
- •Multiple Linux distributions, including Ubuntu and Debian, are affected by this flaw.
- •A patch has been released to fix the vulnerability by validating request origins.
A local privilege escalation vulnerability named 'CIFSwitch' has been discovered in the Linux kernel, enabling low-privileged users to gain root access. This flaw affects multiple Linux distributions that use vulnerable versions of the kernel's CIFS and cifs-utils. The vulnerability arises from the kernel's failure to verify the origin of cifs.spnego key requests, allowing attackers to forge requests. Distributions such as Ubuntu, Debian, and openSUSE are confirmed to be vulnerable under default configurations. A patch has been released to address the issue by validating request origins. The researcher, Asim Manizada, has provided a detailed technical report and proof of concept to aid in assessing exposure. Exploitation depends on several factors, including kernel and cifs-utils versions and specific security policies. Some distributions, including Amazon Linux 2 and certain versions of Kali Linux, are not affected due to their cifs-utils versions lacking the necessary functionality.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…