Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:32990: Important: cifs-utils security update

A local privilege escalation vulnerability (CVE-2026-12505, CVSS 7.8 HIGH) exists in cifs-utils where an attacker can forge a cifs.spnego key description in the cifs.upcall process. This security update for Red Hat Enterprise Linux 10 addresses the flaw. Affected systems should apply the provided cifs-utils package update immediately.
Read Full Article →

Red Hat Product Errata RHSA-2026:32990 - Security Advisory Issued: 2026-06-29 Updated: 2026-06-29 RHSA-2026:32990 - Security Advisory Overview Updated Packages Synopsis Important: cifs-utils security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for cifs-utils is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The SMB/CIFS protocol is a standard file sharing protocol widely deployed on Microsoft Windows machines. The cifs-utils packages contain tools for mounting shares on Linux using the SMB/CIFS protocol. The tools in this package work in conjunction with support in the kernel to allow one to mount a SMB/CIFS share onto a client and use it as if it were a standard Linux file system. Security Fix(es): cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall (CVE-2026-12505) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat CodeReady Linux Builder for x86_64 10 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 10 ppc64le Red Hat CodeReady Linux Builder for ARM 64 10 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 10 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.2 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.2 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2489805 - CVE-2026-12505 cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall CVEs CVE-2026-12505 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM cifs-utils-7.6-1.el10_2.src.rpm SHA-256: 3be9207e75b556807baaf6924d8de39238f1cb3ec7a9ee817ab297be93579e63 x86_64 cifs-utils-7.6-1.el10_2.x86_64.rpm SHA-256: 550834a8c5a2d6b8e480211273579e4d3fb81c45a7fd93c03068a22e44b2d0fd cifs-utils-debuginfo-7.6-1.el10_2.x86_64.rpm SHA-256: 61052f638efe35efe74ed2dd1d3a69a46ad9861361c7b0a92e2b34c62d649266 cifs-utils-debuginfo-7.6-1.el10_2.x86_64.rpm SHA-256: 61052f638efe35efe74ed2dd1d3a69a46ad9861361c7b0a92e2b34c62d649266 cifs-utils-debugsource-7.6-1.el10_2.x86_64.rpm SHA-256: f12f9e416ef540865d6f06b5667bcc9c47035865a4ef23d0669040c223ee8034 cifs-utils-debugsource-7.6-1.el10_2.x86_64.rpm SHA-256: f12f9e416ef540865d6f06b5667bcc9c47035865a4ef23d0669040c223ee8034 pam_cifscreds-7.6-1.el10_2.x86_64.rpm SHA-256: eaf58d4e3566eea13b93b42749a0d18146ff7fdc2900f1480dd396b8d16c03b4 pam_cifscreds-debuginfo-7.6-1.el10_2.x86_64.rpm SHA-256: bd3a70ecb472ec5e210818bf4ae32b9107c7733854b7b54d7d8c98be23737992 pam_cifscreds-debuginfo-7.6-1.el10_2.x86_64.rpm SHA-256: bd3a70ecb472ec5e210818bf4ae32b9107c7733854b7b54d7d8c98be23737992 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM cifs-utils-7.6-1.el10_2.src.rpm SHA-256: 3be9207e75b556807baaf6924d8de39238f1cb3ec7a9ee817ab297be93579e63 x86_64 cifs-utils-7.6-1.el10_2.x86_64.rpm SHA-256: 550834a8c5a2d6b8e480211273579e4d3fb81c45a7fd93c03068a22e44b2d0fd cifs-utils-debuginfo-7.6-1.el10_2.x86_64.rpm SHA-256: 61052f638efe35efe74ed2dd1d3a69a46ad9861361c7b0a92e2b34c62d649266 cifs-utils-debuginfo-7.6-1.el10_2.x86_64.rpm SHA-256: 61052f638efe35efe74ed2dd1d3a69a46ad9861361c7b0a92e2b34c62d649266 cifs-utils-debugsource-7.6-1.el10_2.x86_64.rpm SHA-256: f12f9e416ef540865d6f06b5667bcc9c47035865a4ef23d0669040c223ee8034 cifs-utils-debugsource-7.6-1.el10_2.x86_64.rpm SHA-256: f12f9e416ef540865d6f06b5667bcc9c47035865a4ef23d0669040c223ee8034 pam_cifscreds-7.6-1.el10_2.x86_64.rpm SHA-256: eaf58d4e3566eea13b93b42749a0d18146ff7fdc2900f1480dd396b8d16c03b4 pam_cifscreds-debuginfo-7.6-1.el10_2.x86_64.rpm SHA-256: bd3a70ecb472ec5e210818bf4ae32b9107c7733854b7b54d7d8c98be23737992 pam_cifscreds-debuginfo-7.6-1.el10_2.x86_64.rpm SHA-256: bd3a70ecb472ec5e210818bf4ae32b9107c7733854b7b54d7d8c98be23737992 Red Hat Enterprise Linux for IBM z Systems 10 SRPM cifs-utils-7.6-1.el10_2.src.rpm SHA-256: 3be9207e75b556807baaf6924d8de39238f1cb3ec7a9ee817ab297be93579e63 s390x cifs-utils-7.6-1.el10_2.s390x.rpm SHA-256: 296171f2aea91cdae45d99d301bad47d5c69138c830c09d687a9752187014c2a cifs-utils-debuginfo-7.6-1.el10_2.s390x.rpm SHA-256: c003ef420bcdb2e765cc7510a060c79ddd7b7dcea766e6d57e8f5347202381f2 cifs-utils-debuginfo-7.6-1.el10_2.s390x.rpm SHA-256: c003ef420bcdb2e765cc7510a060c79ddd7b7dcea766e6d57e8f5347202381f2 cifs-utils-debugsource-7.6-1.el10_2.s390x.rpm SHA-256: 8649d70879d1da00af8e50d5a108a9bf27b9a78c9547ea26cab6c313db7527d4 cifs-utils-debugsource-7.6-1.el10_2.s390x.rpm SHA-256: 8649d70879d1da00af8e50d5a108a9bf27b9a78c9547ea26cab6c313db7527d4 pam_cifscreds-7.6-1.el10_2.s390x.rpm SHA-256: ea78e2abd1ef2a86b417be01c6f980114c31090721aa3d442af21e24cb9cc383 pam_cifscreds-debuginfo-7.6-1.el10_2.s390x.rpm SHA-256: 7d76f1e678cc79a0d54927d6a998ca88b75a152bc02e335789775c375da61f2c pam_cifscreds-debuginfo-7.6-1.el10_2.s390x.rpm SHA-256: 7d76f1e678cc79a0d54927d6a998ca88b75a152bc02e335789775c375da61f2c Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 SRPM cifs-utils-7.6-1.el10_2.src.rpm SHA-256: 3be9207e75b556807baaf6924d8de39238f1cb3ec7a9ee817ab297be93579e63 s390x cifs-utils-7.6-1.el10_2.s390x.rpm SHA-256: 296171f2aea91cdae45d99d301bad47d5c69138c830c09d687a9752187014c2a cifs-utils-debuginfo-7.6-1.el10_2.s390x.rpm SHA-256: c003ef420bcdb2e765cc7510a060c79ddd7b7dcea766e6d57e8f5347202381f2 cifs-utils-debuginfo-7.6-1.el10_2.s390x.rpm SHA-256: c003ef420bcdb2e765cc7510a060c79ddd7b7dcea766e6d57e8f5347202381f2 cifs-utils-debugsource-7.6-1.el10_2.s390x.rpm SHA-256: 8649d70879d1da00af8e50d5a108a9bf27b9a78c9547ea26cab6c313db7527d4 cifs-utils-debugsource-7.6-1.el10_2.s390x.rpm SHA-256: 8649d70879d1da00af8e50d5a108a9bf27b9a78c9547ea26cab6c313db7527d4 pam_cifscreds-7.6-1.el10_2.s390x.rpm SHA-256: ea78e2abd1ef2a86b417be01c6f980114c31090721aa3d442af21e24cb9cc383 pam_cifscreds-debuginfo-7.6-1.el10_2.s390x.rpm SHA-256: 7d76f1e678cc79a0d54927d6a998ca88b75a152bc02e335789775c375da61f2c pam_cifscreds-debuginfo-7.6-1.el10_2.s390x.rpm SHA-256: 7d76f1e678cc79a0d54927d6a998ca88b75a152bc02e335789775c375da61f2c Red Hat Enterprise Linux for Power, little endian 10 SRPM cifs-utils-7.6-1.el10_2.src.rpm SHA-256: 3be9207e75b556807baaf6924d8de39238f1cb3ec7a9ee817ab297be93579e63 ppc64le cifs-utils-7.6-1.el10_2.ppc64le.rpm SHA-256: cc717bf1d261c1670be5ca9f8693ea48cb3e34eb05fe1bfbe9e32149578606f7 cifs-utils-debuginfo-7.6-1.el10_2.ppc64le.rpm SHA-256: f261cfe134ca5f9be1623378ff5727017ecd48fec449999abedd73941540e79c cifs-utils-debuginfo-7.6-1.el10_2.ppc64le.rpm SHA-256: f261cfe134ca5f9be1623378ff5727017ecd48fec449999abedd73941540e79c cifs-utils-debugsource-7.6-1.el10_2.ppc64le.rpm SHA-256: 748972bbb9fc05eacf0333577a04b02c67237c0d37678199177a0b7d445d0e9b cifs-utils-debugsource-7.6-1.el10_2.ppc64le.rpm SHA-256: 748972bbb9fc05eacf0333577a04b02c67237c0d37678199177a0b7d445d0e9b pam_cifscreds-7.6-1.el10_2.ppc64le.rpm SHA-256: 1cdcd49a1be115632469905e88f74da1f2ef122548b26acf1f3d6bc67f9e9f2a pam_cifscreds-debuginfo-7.6-1.el10_2.ppc64le.rpm SHA-256: c7a5895be77c1919992be5516701a5f54616d18da27f4b39ea4c6d8ce5040cfc pam_cifscreds-debuginfo-7.6-1.el10_2.ppc64le.rpm SHA-256: c7a5895be77c1919992be5516701a5f54616d18da27f4b39ea4c6d8ce5040cfc Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 SRPM cifs-utils-7.6-1.el10_2.src.rpm SHA-256: 3be9207e75b556807baaf6924d8de39238f1cb3ec7a9ee817ab297be93579e63 ppc64le cifs-utils-7.6-1.el10_2.ppc64le.rpm SHA-256: cc717bf1d261c1670be5ca9f8693ea48cb3e34eb05fe1bfbe9e32149578606f7 cifs-utils-debuginfo-7.6-1.el10_2.ppc64le.rpm SHA-256: f261cfe134ca5f9be1623378ff5727017ecd48fec449999abedd73941540e79c cifs-utils-debuginfo-7.6-1.el10_2.ppc64le.rpm SHA-256: f261cfe134ca5f9be1623378ff5727017ecd48fec449999abedd73941540e79c cifs-utils-debugsource-7.6-1.el10_2.ppc64le.rpm SHA-256: 748972bbb9fc05eacf0333577a04b02c67237c0d37678199177a0b7d445d0e9b cifs-utils-debugsource-7.6-1.el10_2.ppc64le.rpm SHA-256: 748972bbb9fc05eacf0333577a04b02c67237c0d37678199177

Share this article