A flaw was found in cifs-utils. When trying to obtain Kerberos credentials, the cifs.upcall program from the cifs-utils package makes an upcall to the wrong namespace in containerized environments. This issue may lead to disclosing sensitive data from the host's Kerberos credentials cache.
2025-03-25T18:15:34.987
2025-03-27T16:45:46.410
Awaiting Analysis
74b3a70d-cca6-4d34-9789-e83b222ae3be
CVSSv3.1: 5.9 (MEDIUM)
-