Beveiligingsadvies

CVE-2025-2312

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-03-25 18:08:02
Laatst bijgewerkt 2025-03-25 18:23:15
Toegewezen door redhat-cnalr
CVSS-score 5.9
Status PUBLISHED

Beschrijving

A flaw was found in cifs-utils. When trying to obtain Kerberos credentials, the cifs.upcall program from the cifs-utils package makes an upcall to the wrong namespace in containerized environments. This issue may lead to disclosing sensitive data from the host's Kerberos credentials cache.