UbuntuUpdates.org

Package "cifs-utils"

Name: cifs-utils

Description:

Common Internet File System utilities

Latest version: 2:7.2-2ubuntu0.1
Release: plucky (25.04)
Level: updates
Repository: main
Homepage: https://wiki.samba.org/index.php/LinuxCIFS_utils

Links


Download "cifs-utils"


Other versions of "cifs-utils" in Plucky

Repository Area Version
base main 2:7.2-2
security main 2:7.2-2ubuntu0.1

Changelog

Version: 2:7.2-2ubuntu0.1 2025-06-16 18:07:46 UTC

  cifs-utils (2:7.2-2ubuntu0.1) plucky-security; urgency=medium

  * SECURITY REGRESSION: Fix memory leak in check_service_ticket_exists()
    if a valid Kerberos service ticket is not available.
    (LP: #2113906)
    - d/p/lp2113906-cifs.upcall-fix-memory-leaks-in-check_service_ticket.patch
  * SECURITY REGRESSION: Correctly search the calling applications
    environment for KRB5CCNAME if running kernel is not patched for
    CVE-2025-2312, fixing mounts for AD users. (LP: #2112614)
    - d/p/CVE-2025-2312-3.patch: cifs.upcall: correctly treat
      UPTARGET_UNSPECIFIED as UPTARGET_APP.

 -- Matthew Ruffell <email address hidden> Wed, 11 Jun 2025 15:33:36 +1200

2113906 Regression: After LP2099917 cifs.upcall leaks memory on error message if service ticket doesn't exist
2112614 Regression: After CVE-2025-2312 cifs.upcall can't find credential caches from user env
CVE-2025-2312 A flaw was found in cifs-utils. When trying to obtain Kerberos credentials, the cifs.upcall program from the cifs-utils package makes an upcall to th



About   -   Send Feedback to @ubuntu_updates