Ubuntu alert USN-8496-1 (cifs-utils)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8496-1] cifs-utils vulnerability | |
| Date: | Thu, 02 Jul 2026 15:35:53 +0000 | |
| Message-ID: | <E1wfJSD-0007MK-9k@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8496-1 July 02, 2026 cifs-utils vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: cifs-utils could be made to run programs as an administrator. Software Description: - cifs-utils: Common Internet File System utilities Details: It was discovered that cifs-utils incorrectly dropped root privileges before looking up user information. A local attacker could possibly use this issue to execute arbitrary code as the root user. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS cifs-utils 2:7.4-1ubuntu0.26.04.1 Ubuntu 25.10 cifs-utils 2:7.4-1ubuntu0.25.10.1 Ubuntu 24.04 LTS cifs-utils 2:7.0-2ubuntu0.3 Ubuntu 22.04 LTS cifs-utils 2:6.14-1ubuntu0.4 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8496-1 CVE-2026-12505 Package Information: https://launchpad.net/ubuntu/+source/cifs-utils/2:7.4-1ub... https://launchpad.net/ubuntu/+source/cifs-utils/2:7.4-1ub... https://launchpad.net/ubuntu/+source/cifs-utils/2:7.0-2ub... https://launchpad.net/ubuntu/+source/cifs-utils/2:6.14-1u...
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmpGhRoACgkQcpJm3tlz hgGxkhAAip/2z2rxTxtD5KVU4cJle9Ej2F+7Kf6zAkQ4yD1/w5qqXRdlvSZbeRnz UlnjN01DDfq7qalAwNfbdzzzqVm70fzXkQiJjpcZWvOYHX/aezYnHhLkarukK2dL /1jH+3lrFXa2sO00Rb0ea1PuZLUTVveWmZ+dvkusN1oEsrGbrqfVnOsRBEkqTzOi i5WxzcXx9ha4BPG37PVCwQz5t+36o6JkOUlWf91WLq4nzrw5oTX4w5izzrvLrH6p YXFDhU3XF7G/Y4j1y00eKVRF/qXYMsUuysIPSPf8wUJKIRH89NZaotRMV3A2T3LQ qemeoIL+FgGHKVj7hdr9hoIRNs5kaUjxYAExsEf1uF+HaXPvfyTs4F3NfETfnlg2 IHfBDwr3JyVfVVTfYbtWRm4bihmwdEeqIfDABZ9LpdeDw07vm56/WJZ6t1dU2424 t0zkgf7Sq3q/PmswBuR3DnOf83RkV6Y/si+pHLoOcwub7ZW02JD2m16x8m/lvtPE +3+uXd3Bmavy4odBD6A4jGbBIVaHNlv1DF87u/T+bpgZP3dylSO/taEONlMhPrVE HLzdWXi6HxFDJtS44B2dIG1FUcqVco1XpA8T+mhRFbz0CM6s/bzDoRx6u9qD+ULE Uob8VR26oOKQpOJ3BymS0IiIMyYuQ1OKW+DXSKHiuZhfPii7eIk= =p4BM -----END PGP SIGNATURE-----
