DigiNews

Tech Watch by Johan Denoyer

← Back to articles

CIFSwitch: a non-universal Linux local root vulnerability

Quality: 8/10 Relevance: 9/10

Summary

CIFSwitch documents a Linux local root vulnerability in the CIFS/spnego flow, showing how a forged cifs.spnego key description can trigger cifs.upcall as root and move into an attacker-controlled namespace, then perform an NSS-based privilege escalation. The piece includes exploitation details, affected distributions, mitigations, and patch status.

🚀 Service construit par Johan Denoyer