{"id":181796,"date":"2026-05-29T14:48:11","date_gmt":"2026-05-29T12:48:11","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/cifswitch-uyazvimost-v-cifs-podsisteme-yadra-linux-pozvolyayushhaya-poluchit-prava-root"},"modified":"2026-05-29T14:48:11","modified_gmt":"2026-05-29T12:48:11","slug":"cifswitch-uyazvimost-v-cifs-podsisteme-yadra-linux-pozvolyayushhaya-poluchit-prava-root","status":"publish","type":"post","link":"https:\/\/prohoster.info\/nl\/blog\/news\/cifswitch-uyazvimost-v-cifs-podsisteme-yadra-linux-pozvolyayushhaya-poluchit-prava-root","title":{"rendered":"CIFSwitch \u2014 een kwetsbaarheid in de CIFS-subsys van de Linux-kernel die root-rechten kan verkrijgen","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Details have been revealed and an exploit has been published for the CIFSwitch vulnerability (CVE not yet assigned) in the CIFS kernel module and the cifs-utils toolkit, allowing an unprivileged user to gain root rights in the system. The fix is only available as a patch, which was published on May 16 and accepted into the main branch of the Linux kernel on May 19 (corrective kernel releases are not yet available). <\/p>\n<p>The vulnerability affects the code that provides support for the cifs.spnego mechanism for authentication via the SPNEGO (Simple and Protected GSSAPI Negotiation) protocol when connecting to SMB servers. When using cifs.spnego to determine keys from Kerberos\/SPNEGO, the kernel invokes the cifs.upcall handler, provided by the cifs-utils package and executed in user space with root rights. <\/p>\n<p>Een niet-geprivilegieerde gebruiker kan een oproep naar de handler initi\u00ebren door een verzoek te sturen waarin gevraagd wordt om de sleutel &#171;cifs.spnego&#187;, met een valse beschrijving &#171;CIFS SPNEGO&#187;. In de cifs.upcall handler worden geen extra controles op de geldigheid van de parameters uitgevoerd die via de kernel zijn doorgegeven; onder andere beschouwt deze vertrouwde waarden voor de velden pid, uid, creduid en<br \/>\n  upcall_target as trustworthy. Once activated, the cifs.upcall handler switches into the namespaces of the user process that sent the request, and before privilege drop, it searches the NSS (Name Service Switch) system database.<\/p>\n<p>An attacker can launch their process in a separate mount namespace, leading to the NSS request being executed in their context. To exploit the vulnerability, it is sufficient for the attacker to place their own configuration file \/etc\/nsswitch.conf and a set of spoofed libraries libnss_*.so.2 in the environment they created. Executing an NSS request by the cifs.upcall handler will lead to loading the spoofed libraries with root rights.<\/p>\n<p>To exploit the vulnerability, the system must allow the creation of user namespaces or mount namespaces, and the cifs-utils package must be installed on the system. The distributions where the vulnerability can be exploited with the default configuration include:<\/p>\n<ul>\n<li> Linux Mint Cinnamon 21.3\/22.3\n<li> CentOS Stream 9 GNOME\n<li> Rocky Linux 9 Workstation\n<li> Kali Linux\n<li> AlmaLinux 9.7 Workstation\n<li> SUSE 15 SP7\/SAP 15 SP7\/SAP 16\n<\/ul>\n<p>Distributies waarvoor de installatie van het cifs-utils-pakket nodig is om de exploit te laten werken: <\/p>\n<ul>\n<li> Ubuntu 18.04\/20.04\/22.04 Desktop\/Server\n<li> Pop!_OS 22.04 Intel\/24.04 Generic\n<li> Ubuntu 24.04 Desktop minimal\/volledig en Server\n<li> Debian 11\/12\/13 netinst standaard en GNOME\/KDE\/standaard\/XFCE\n<li> CentOS Stream 9 Cinnamon\/KDE\/MATE\/XFCE\n<li> Rocky Linux 9 KDE\/Workstation-Lite\n<li> openSUSE Leap 15.6 GNOME\/KDE\n<li> openSUSE Tumbleweed GNOME\/KDE\n<li> Rocky Linux 8 GenericCloud\n<li> Oracle Linux 8\/9 <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/nl\/vps\/abuzoustojchivye-vps\/\" title=\"KVM\" data-wpil-keyword-link=\"linked\">KVM<\/a>\n<li> Amazon Linux 2023 KVM\n<\/ul>\n<p>Distributies waarbij in de standaardconfiguratie instellingen worden toegepast die de exploitatie van de kwetsbaarheid via SELinux of Apparmor blokkeren, zelfs met het cifs-utils-pakket aanwezig: <\/p>\n<ul>\n<li> Ubuntu 26.04 Desktop\/Server\n<li> Fedora 40\/41\/42\/43\/44 Workstation\/Server\n<li> CentOS Stream 10 GNOME\/KDE\n<li> Rocky Linux 10 Workstation\n<li> AlmaLinux 10.1 Workstation\n<li> Oracle Linux 10 KVM\n<li> openSUSE Tumbleweed GNOME\/KDE\n<li> openSUSE Leap 16.0 OEM GNOME\/KDE\/Minimal-VM\n<li> SUSE Linux 16\n<\/ul>\n<p>Als een omweg om bescherming te bieden, kan de automatische laadtijd van de cifs-kernelmodule worden geblokkeerd:<\/p>\n<p>   sh -c &#171;printf &#8216;install cifs \/bin\/false&#092;n&#8217; &gt; \/etc\/modprobe.d\/cifs.conf; rmmod cifs 2&gt;\/dev\/null; true&#187;<\/p>\n<p>Het is ook mogelijk om het gebruik van user namespace te verbieden (&#171;sysctl -w kernel.unprivileged_userns_clone=0&#187;) en de regel cifs.spnego in de cifs-utils instellingen te verwijderen of te overschrijven:<\/p>\n<p>    cat &gt;\/etc\/request-key.d\/cifs.spnego.conf &lt;&#8216;EOF&#8217;<br \/>\n    create cifs.spnego * * \/usr\/sbin\/keyctl negate %k 30 %S<br \/>\n    EOF<\/p>\n<p>In de tussentijd zijn er op 28 mei 137 meldingen van kwetsbaarheden in de Linux kernel gepubliceerd, en op 27 mei waren dat er 277.<br \/>\n<br \/>Bron: <a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=65572\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u044b \u0434\u0435\u0442\u0430\u043b\u0438 \u0438 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u044d\u043a\u0441\u043f\u043b\u043e\u0438\u0442 \u0434\u043b\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 CIFSwitch (CVE \u043f\u043e\u043a\u0430 \u043d\u0435 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d) \u0432 \u043c\u043e\u0434\u0443\u043b\u0435 \u044f\u0434\u0440\u0430 CIFS \u0438 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u0430\u0440\u0438\u0438 cifs-utils, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u043f\u0440\u0430\u0432\u0430 root \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435. \u0418\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0435 \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u043e \u0442\u043e\u043b\u044c\u043a\u043e \u0432 \u0432\u0438\u0434\u0435 \u043f\u0430\u0442\u0447\u0430, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d 16 \u043c\u0430\u044f \u0438 19 \u043c\u0430\u044f \u0431\u044b\u043b \u043f\u0440\u0438\u043d\u044f\u0442 \u0432 \u043e\u0441\u043d\u043e\u0432\u043d\u0443\u044e \u0432\u0435\u0442\u043a\u0443 \u044f\u0434\u0440\u0430 Linux (\u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u0432\u044b\u043f\u0443\u0441\u043a\u0438 \u044f\u0434\u0440\u0430 \u0435\u0449\u0451 \u043d\u0435\u0434\u043e\u0441\u0442\u0443\u043f\u043d\u044b). \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u0435\u0442 \u043a\u043e\u0434, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":8,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-181796","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.3 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u044b \u0434\u0435\u0442\u0430\u043b\u0438 \u0438 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u044d\u043a\u0441\u043f\u043b\u043e\u0438\u0442 \u0434\u043b\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 CIFSwitch (CVE \u043f\u043e\u043a\u0430 \u043d\u0435 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d) \u0432 \u043c\u043e\u0434\u0443\u043b\u0435 \u044f\u0434\u0440\u0430 CIFS \u0438 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u0430\u0440\u0438\u0438 cifs-utils, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u043f\u0440\u0430\u0432\u0430 root \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Erik Peterson\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/nl\/blog\/news\/cifswitch-uyazvimost-v-cifs-podsisteme-yadra-linux-pozvolyayushhaya-poluchit-prava-root\" \/>\n\t\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.3\" \/>\n\t\t<meta property=\"og:locale\" content=\"nl_NL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47CIFSwitch \u2014 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 CIFS-\u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u044f\u0434\u0440\u0430 Linux, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u043f\u0440\u0430\u0432\u0430 root | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u044b \u0434\u0435\u0442\u0430\u043b\u0438 \u0438 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u044d\u043a\u0441\u043f\u043b\u043e\u0438\u0442 \u0434\u043b\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 CIFSwitch (CVE \u043f\u043e\u043a\u0430 \u043d\u0435 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d) \u0432 \u043c\u043e\u0434\u0443\u043b\u0435 \u044f\u0434\u0440\u0430 CIFS \u0438 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u0430\u0440\u0438\u0438 cifs-utils, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u043f\u0440\u0430\u0432\u0430 root \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/nl\/blog\/news\/cifswitch-uyazvimost-v-cifs-podsisteme-yadra-linux-pozvolyayushhaya-poluchit-prava-root\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-05-29T12:48:11+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-05-29T12:48:11+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47CIFSwitch \u2014 een kwetsbaarheid in de CIFS-subsystem van de Linux-kernel, waardoor root-rechten verkregen kunnen worden | ProHoster","description":"Details zijn onthuld en een exploit is gepubliceerd voor de kwetsbaarheid CIFSwitch (CVE nog niet toegewezen) in de CIFS-kernelmodule en de cifs-utils-toolkit, waardoor een niet-privilege gebruiker root-rechten op het systeem kan verkrijgen.","canonical_url":"https:\/\/prohoster.info\/nl\/blog\/news\/cifswitch-uyazvimost-v-cifs-podsisteme-yadra-linux-pozvolyayushhaya-poluchit-prava-root","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"nl_NL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47CIFSwitch \u2014 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 CIFS-\u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u044f\u0434\u0440\u0430 Linux, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u043f\u0440\u0430\u0432\u0430 root | ProHoster","og:description":"\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u044b \u0434\u0435\u0442\u0430\u043b\u0438 \u0438 \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u044d\u043a\u0441\u043f\u043b\u043e\u0438\u0442 \u0434\u043b\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 CIFSwitch (CVE \u043f\u043e\u043a\u0430 \u043d\u0435 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d) \u0432 \u043c\u043e\u0434\u0443\u043b\u0435 \u044f\u0434\u0440\u0430 CIFS \u0438 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u0430\u0440\u0438\u0438 cifs-utils, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044e \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u043f\u0440\u0430\u0432\u0430 root \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435.","og:url":"https:\/\/prohoster.info\/nl\/blog\/news\/cifswitch-uyazvimost-v-cifs-podsisteme-yadra-linux-pozvolyayushhaya-poluchit-prava-root","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-05-29T12:48:11+00:00","article:modified_time":"2026-05-29T12:48:11+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/posts\/181796","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/comments?post=181796"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/posts\/181796\/revisions"}],"predecessor-version":[{"id":182094,"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/posts\/181796\/revisions\/182094"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/media?parent=181796"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/categories?post=181796"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/tags?post=181796"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}