CVE-2025-2312

Source
https://cve.org/CVERecord?id=CVE-2025-2312
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-2312.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-2312
Downstream
Related
Published
2025-03-25T18:08:02.848Z
Modified
2026-05-08T04:56:33.860429Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N CVSS Calculator
Summary
cifs.upcall makes an upcall to the wrong namespace in containerized environments
Details

A flaw was found in cifs-utils. When trying to obtain Kerberos credentials, the cifs.upcall program from the cifs-utils package makes an upcall to the wrong namespace in containerized environments. This issue may lead to disclosing sensitive data from the host's Kerberos credentials cache.

Database specific
{
    "cwe_ids": [
        "CWE-488"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/2xxx/CVE-2025-2312.json",
    "cna_assigner": "redhat-cnalr"
}
References

Affected packages

Git / git.samba.org/cifs-utils.git/

Affected ranges

Type
GIT
Repo
https://git.samba.org/cifs-utils.git/
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
0da208dab49b34ca825cee37cb1817e449d52444
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "7.2"
        }
    ]
}

Affected versions

cifs-utils-4.*
cifs-utils-4.0
cifs-utils-4.0a1
cifs-utils-4.0rc1
cifs-utils-4.1
cifs-utils-4.2
cifs-utils-4.3
cifs-utils-4.4
cifs-utils-4.5
cifs-utils-4.6
cifs-utils-4.7
cifs-utils-4.8
cifs-utils-4.8.1
cifs-utils-4.9
cifs-utils-5.*
cifs-utils-5.0
cifs-utils-5.1
cifs-utils-5.2
cifs-utils-5.3
cifs-utils-5.4
cifs-utils-5.5
cifs-utils-5.6
cifs-utils-5.7
cifs-utils-5.8
cifs-utils-5.9
cifs-utils-6.*
cifs-utils-6.0
cifs-utils-6.1
cifs-utils-6.10
cifs-utils-6.11
cifs-utils-6.12
cifs-utils-6.13
cifs-utils-6.14
cifs-utils-6.15
cifs-utils-6.2
cifs-utils-6.3
cifs-utils-6.4
cifs-utils-6.5
cifs-utils-6.6
cifs-utils-6.7
cifs-utils-6.8
cifs-utils-6.9
cifs-utils-7.*
cifs-utils-7.0
cifs-utils-7.1
Other
release-4-0a1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-2312.json"