news
CIFSwitch Bug in Linux and Other Defects in the Kernel
-
Security Week ☛ 19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access
When authenticating a mount, the subsystem sends a request_key call for a cifs.spnego key. The request checks the key in userspace and calls cifs.upcall as root to parse the key description, which contains fields such as UID, PID, credential cache, and namespace.
-
SUSE Linux Kernel Multiple Vulnerabilities
Multiple vulnerabilities were identified in SUSE Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger cross-site scripting, denial of service condition, elevation of privilege, security restriction bypass, sensitive information disclosure, remote code execution and data manipulation on the targeted system.
-
Security Affairs ☛ CIFSwitch, a Linux Root Bug Hidden in Plain Sight for 19 Years