VYPR
Medium severity5.9NVD Advisory· Published Mar 25, 2025· Updated Jun 17, 2026

CVE-2025-2312

CVE-2025-2312

Description

A flaw was found in cifs-utils. When trying to obtain Kerberos credentials, the cifs.upcall program from the cifs-utils package makes an upcall to the wrong namespace in containerized environments. This issue may lead to disclosing sensitive data from the host's Kerberos credentials cache.

Affected products

120

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.