CVE-2025-2312

Publication date

2025-03-25 18:08:02

Family

redhat-cnalr

State

PUBLISHED

Description

A flaw was found in cifs-utils. When trying to obtain Kerberos credentials, the cifs.upcall program from the cifs-utils package makes an upcall to the wrong namespace in containerized environments. This issue may lead to disclosing sensitive data from the hosts Kerberos credentials cache.