VYPR
Medium severity5.9NVD Advisory· Published Mar 25, 2025· Updated Apr 15, 2026

CVE-2025-2312

CVE-2025-2312

Description

A flaw was found in cifs-utils. When trying to obtain Kerberos credentials, the cifs.upcall program from the cifs-utils package makes an upcall to the wrong namespace in containerized environments. This issue may lead to disclosing sensitive data from the host's Kerberos credentials cache.

Affected products

119

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.