VYPR

cifs-utils

by Red Hat

CVEs (1)

  • CVE-2026-12505HigJun 18, 2026
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to…