[CLSA-2026:1784818499] cifs-utils: Fix of CVE-2026-12505
Type:
security
Severity:
Important
Release date:
2026-07-23 14:55:30 UTC
Description:
- CVE-2026-12505: perform the user lookup and drop supplementary groups on the host namespace before switching to the caller namespace, fixing a local privilege escalation in cifs.upcall
CVEs fixed:
Updated packages:
  • cifs-utils-7.0-1.el9.tuxcare.els1.x86_64.rpm
    sha:9ed931b82773d511914bd17586776d6e7bdb6337accbed75c4c1c9a6e567f975
  • cifs-utils-devel-7.0-1.el9.tuxcare.els1.i686.rpm
    sha:ad3805e30246a670f4705a52b3ad0bc18e4890cc44b061ae34774c27148ae436
  • cifs-utils-devel-7.0-1.el9.tuxcare.els1.x86_64.rpm
    sha:1284c76b03bf80158eb893cc2f7842bcaa7b3bceaa13ddea3a1ed7da3b862bda
  • cifs-utils-info-7.0-1.el9.tuxcare.els1.x86_64.rpm
    sha:979df9822005e4174aed4de3e07f42fa387d0faaa300a8b6535f154302b7f5c2
  • pam_cifscreds-7.0-1.el9.tuxcare.els1.x86_64.rpm
    sha:3d87bbbbca5cbb65832ed2995a5fd7046720161dc82a2fc5cc75ba96b3e2904c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.