UbuntuUpdates.org

Package "cifs-utils"

Name: cifs-utils

Description:

Common Internet File System utilities

Latest version: 2:7.0-2.1ubuntu0.1
Release: oracular (24.10)
Level: updates
Repository: main
Homepage: https://www.samba.org/~jlayton/cifs-utils/

Links


Download "cifs-utils"


Other versions of "cifs-utils" in Oracular

Repository Area Version
base main 2:7.0-2.1
security main 2:7.0-2.1ubuntu0.1

Changelog

Version: 2:7.0-2.1ubuntu0.1 2025-05-27 21:07:29 UTC

  cifs-utils (2:7.0-2.1ubuntu0.1) oracular-security; urgency=medium

  * Skip checking the Kerberos TGT if a valid service ticket
    is available. (LP: #2099917)
    - d/p/lp2099917-cifs-utils-Skip-TGT-check-if-valid-service.patch
  * SECURITY UPDATE: namespace confusion may lead to disclosing
    sensitive data from host Kerberos credentials cache. (LP: #2099914)
    - d/p/CVE-2025-2312-1.patch: CIFS.upcall to accomodate new
      namespace mount opt.
    - d/p/CVE-2025-2312-2.patch: cifs-utils: add documentation
      for upcall_target.
    - CVE-2025-2312

 -- Matthew Ruffell <email address hidden> Wed, 02 Apr 2025 15:48:31 +1300

2099917 cifs.upcall: If kerberos credential cache already contains a valid service ticket, use that even if TGT is expired
CVE-2025-2312 A flaw was found in cifs-utils. When trying to obtain Kerberos credentials, the cifs.upcall program from the cifs-utils package makes an upcall to th



About   -   Send Feedback to @ubuntu_updates