Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-2312


A flaw was found in cifs-utils. When trying to obtain Kerberos credentials, the cifs.upcall program from the cifs-utils package makes an upcall to the wrong namespace in containerized environments. This issue may lead to disclosing sensitive data from the host's Kerberos credentials cache.


Published

2025-03-25T18:15:34.987

Last Modified

2025-03-27T16:45:46.410

Status

Awaiting Analysis

Source

74b3a70d-cca6-4d34-9789-e83b222ae3be

Severity

CVSSv3.1: 5.9 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-488

Affected Vendors & Products

-


References