Ubuntu Security Notices USN-8496-1 USN-8496-1: cifs-utils vulnerability Publication date 2 July 2026 Overview cifs-utils could be made to run programs as an administrator. Releases 26.04 LTS 25.10 24.04 LTS 22.04 LTS Open side navigation Close side navigation Packages Details Update instructions References Packages cifs-utils - Common Internet File System utilities Details It was discovered that cifs-utils incorrectly dropped root privileges before looking up user information. A local attacker could possibly use this issue to execute arbitrary code as the root user. It was discovered that cifs-utils incorrectly dropped root privileges before looking up user information. A local attacker could possibly use this issue to execute arbitrary code as the root user. Update instructions In general, a standard system update will make all the necessary changes. Learn more about how to get the fixes. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 26.04 LTS resolute cifs-utils – 2:7.4-1ubuntu0.26.04.1 25.10 questing cifs-utils – 2:7.4-1ubuntu0.25.10.1 24.04 LTS noble cifs-utils – 2:7.0-2ubuntu0.3 22.04 LTS jammy cifs-utils – 2:6.14-1ubuntu0.4 Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References CVE-2026-12505 CVE-2026-12505
A local privilege escalation vulnerability (CVE-2026-12505) in cifs-utils occurs when the utility incorrectly drops root privileges before performing user lookups, allowing a local attacker to execute arbitrary code with root privileges. Affected Ubuntu releases include 22.04 LTS (jammy), 24.04 LTS (noble), 25.10 (questing), and 26.04 LTS (resolute). The fix requires updating to specific package versions, such as cifs-utils 2:7.4-1ubuntu0.26.04.1 for Ubuntu 26.04 LTS, via a standard system update.