Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:39576: Important: cifs-utils security, bug fix, and enhancement update

A local privilege escalation vulnerability (CVE-2026-12505) in cifs-utils allows an attacker to forge a cifs.spnego key description in the cifs.upcall process. This security advisory, rated Important, applies to Red Hat Enterprise Linux 9 and its Extended Update Support variants. The fix is included in the updated cifs-utils packages released via Red Hat Errata RHSA-2026:39576.
Read Full Article →

Red Hat Product Errata RHSA-2026:39576 - Security Advisory Issued: 2026-07-15 Updated: 2026-07-15 RHSA-2026:39576 - Security Advisory Overview Updated Packages Synopsis Important: cifs-utils security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for cifs-utils is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The SMB/CIFS protocol is a standard file sharing protocol widely deployed on Microsoft Windows machines. The cifs-utils packages contain tools for mounting shares on Linux using the SMB/CIFS protocol. The tools in this package work in conjunction with support in the kernel to allow one to mount a SMB/CIFS share onto a client and use it as if it were a standard Linux file system. Security Fix(es): cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall (CVE-2026-12505) Bug Fix(es) and Enhancement(s): cifs-utils: regression with kerberos mount [rhel-9.8.z] (JIRA:RHEL-192982) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat CodeReady Linux Builder for x86_64 9 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le Red Hat CodeReady Linux Builder for ARM 64 9 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.8 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.8 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2489805 - CVE-2026-12505 cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall CVEs CVE-2026-12505 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM cifs-utils-7.6-2.el9_8.src.rpm SHA-256: 3f326579ba7916bd17eca5524a1c7f3dbb115a0f71e0e6ebee6fca38ecbc913f x86_64 cifs-utils-7.6-2.el9_8.x86_64.rpm SHA-256: 4f5176fed7b69c7b256943004c5ef176b99da23cb451f8a1e2809602c8a784ff cifs-utils-debuginfo-7.6-2.el9_8.x86_64.rpm SHA-256: 62748afcf107c12a93e9d4177f82782eac05254231773e62c47d6419927de667 cifs-utils-debuginfo-7.6-2.el9_8.x86_64.rpm SHA-256: 62748afcf107c12a93e9d4177f82782eac05254231773e62c47d6419927de667 cifs-utils-debugsource-7.6-2.el9_8.x86_64.rpm SHA-256: 254efb8f15565e0c345ed587a1358d9d9aeee08872e49d380e1ea9656eba7a9e cifs-utils-debugsource-7.6-2.el9_8.x86_64.rpm SHA-256: 254efb8f15565e0c345ed587a1358d9d9aeee08872e49d380e1ea9656eba7a9e pam_cifscreds-7.6-2.el9_8.x86_64.rpm SHA-256: 2b0f7d78f22576028ba6501e7db4bb6a8f3925c9f30a0b9c1f00bee820bdedb8 pam_cifscreds-debuginfo-7.6-2.el9_8.x86_64.rpm SHA-256: 50d068df9631f0ee2957a9cb6aebea2d19d742f03923d1111e08f387c6711b74 pam_cifscreds-debuginfo-7.6-2.el9_8.x86_64.rpm SHA-256: 50d068df9631f0ee2957a9cb6aebea2d19d742f03923d1111e08f387c6711b74 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 SRPM cifs-utils-7.6-2.el9_8.src.rpm SHA-256: 3f326579ba7916bd17eca5524a1c7f3dbb115a0f71e0e6ebee6fca38ecbc913f x86_64 cifs-utils-7.6-2.el9_8.x86_64.rpm SHA-256: 4f5176fed7b69c7b256943004c5ef176b99da23cb451f8a1e2809602c8a784ff cifs-utils-debuginfo-7.6-2.el9_8.x86_64.rpm SHA-256: 62748afcf107c12a93e9d4177f82782eac05254231773e62c47d6419927de667 cifs-utils-debuginfo-7.6-2.el9_8.x86_64.rpm SHA-256: 62748afcf107c12a93e9d4177f82782eac05254231773e62c47d6419927de667 cifs-utils-debugsource-7.6-2.el9_8.x86_64.rpm SHA-256: 254efb8f15565e0c345ed587a1358d9d9aeee08872e49d380e1ea9656eba7a9e cifs-utils-debugsource-7.6-2.el9_8.x86_64.rpm SHA-256: 254efb8f15565e0c345ed587a1358d9d9aeee08872e49d380e1ea9656eba7a9e pam_cifscreds-7.6-2.el9_8.x86_64.rpm SHA-256: 2b0f7d78f22576028ba6501e7db4bb6a8f3925c9f30a0b9c1f00bee820bdedb8 pam_cifscreds-debuginfo-7.6-2.el9_8.x86_64.rpm SHA-256: 50d068df9631f0ee2957a9cb6aebea2d19d742f03923d1111e08f387c6711b74 pam_cifscreds-debuginfo-7.6-2.el9_8.x86_64.rpm SHA-256: 50d068df9631f0ee2957a9cb6aebea2d19d742f03923d1111e08f387c6711b74 Red Hat Enterprise Linux for IBM z Systems 9 SRPM cifs-utils-7.6-2.el9_8.src.rpm SHA-256: 3f326579ba7916bd17eca5524a1c7f3dbb115a0f71e0e6ebee6fca38ecbc913f s390x cifs-utils-7.6-2.el9_8.s390x.rpm SHA-256: 24d2d23ae6e4d0cffa58970dd6598da4d0651fc9bd007e9ae3616ab0aee2323c cifs-utils-debuginfo-7.6-2.el9_8.s390x.rpm SHA-256: 56e58b600eb1099c301d51077a572d73c78671d2e9ff6ba19fb3b30489612efd cifs-utils-debuginfo-7.6-2.el9_8.s390x.rpm SHA-256: 56e58b600eb1099c301d51077a572d73c78671d2e9ff6ba19fb3b30489612efd cifs-utils-debugsource-7.6-2.el9_8.s390x.rpm SHA-256: 460c148cab83f75628a9b184e12c30742ff0dd7f7ebe086d9b3249f79cfd4ce4 cifs-utils-debugsource-7.6-2.el9_8.s390x.rpm SHA-256: 460c148cab83f75628a9b184e12c30742ff0dd7f7ebe086d9b3249f79cfd4ce4 pam_cifscreds-7.6-2.el9_8.s390x.rpm SHA-256: 9b478d91193a8785eaec9d0b0165419bcd6d9dc3f57573c08edae67cfa71bea4 pam_cifscreds-debuginfo-7.6-2.el9_8.s390x.rpm SHA-256: a65accabe728749d4e9b113c1c4c19653716f6daf3e0d5f164a5ae777e394228 pam_cifscreds-debuginfo-7.6-2.el9_8.s390x.rpm SHA-256: a65accabe728749d4e9b113c1c4c19653716f6daf3e0d5f164a5ae777e394228 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 SRPM cifs-utils-7.6-2.el9_8.src.rpm SHA-256: 3f326579ba7916bd17eca5524a1c7f3dbb115a0f71e0e6ebee6fca38ecbc913f s390x cifs-utils-7.6-2.el9_8.s390x.rpm SHA-256: 24d2d23ae6e4d0cffa58970dd6598da4d0651fc9bd007e9ae3616ab0aee2323c cifs-utils-debuginfo-7.6-2.el9_8.s390x.rpm SHA-256: 56e58b600eb1099c301d51077a572d73c78671d2e9ff6ba19fb3b30489612efd cifs-utils-debuginfo-7.6-2.el9_8.s390x.rpm SHA-256: 56e58b600eb1099c301d51077a572d73c78671d2e9ff6ba19fb3b30489612efd cifs-utils-debugsource-7.6-2.el9_8.s390x.rpm SHA-256: 460c148cab83f75628a9b184e12c30742ff0dd7f7ebe086d9b3249f79cfd4ce4 cifs-utils-debugsource-7.6-2.el9_8.s390x.rpm SHA-256: 460c148cab83f75628a9b184e12c30742ff0dd7f7ebe086d9b3249f79cfd4ce4 pam_cifscreds-7.6-2.el9_8.s390x.rpm SHA-256: 9b478d91193a8785eaec9d0b0165419bcd6d9dc3f57573c08edae67cfa71bea4 pam_cifscreds-debuginfo-7.6-2.el9_8.s390x.rpm SHA-256: a65accabe728749d4e9b113c1c4c19653716f6daf3e0d5f164a5ae777e394228 pam_cifscreds-debuginfo-7.6-2.el9_8.s390x.rpm SHA-256: a65accabe728749d4e9b113c1c4c19653716f6daf3e0d5f164a5ae777e394228 Red Hat Enterprise Linux for Power, little endian 9 SRPM cifs-utils-7.6-2.el9_8.src.rpm SHA-256: 3f326579ba7916bd17eca5524a1c7f3dbb115a0f71e0e6ebee6fca38ecbc913f ppc64le cifs-utils-7.6-2.el9_8.ppc64le.rpm SHA-256: 3843cc9a942144bd7426f9930f96d85ee5bf2aa28c92200c73d0c92843d055a5 cifs-utils-debuginfo-7.6-2.el9_8.ppc64le.rpm SHA-256: c03d83fcaa371b3e71815cd969244827c53907eb035dafdf222adc64a53eebb9 cifs-utils-debuginfo-7.6-2.el9_8.ppc64le.rpm SHA-256: c03d83fcaa371b3e71815cd969244827c53907eb035dafdf222adc64a53eebb9 cifs-utils-debugsource-7.6-2.el9_8.ppc64le.rpm SHA-256: 83644a188d1456212513a9d05e7faea5eac88e164fd4ada2544b004118f997ec cifs-utils-debugsource-7.6-2.el9_8.ppc64le.rpm SHA-256: 83644a188d1456212513a9d05e7faea5eac88e164fd4ada2544b004118f997ec pam_cifscreds-7.6-2.el9_8.ppc64le.rpm SHA-256: d8c42db8d3c71d9ec977c1acb3808b90d4bd45bb4e572111113a6fbe04321fd3 pam_cifscreds-debuginfo-7.6-2.el9_8.ppc64le.rpm SHA-256: eeb97a1f5b5123401c10c1d79cabc5d6479c9a1713a406c6f5f860e9275d4abf pam_cifscreds-debuginfo-7.6-2.el9_8.ppc64le.rpm SHA-256: eeb97a1f5b5123401c10c1d79cabc5d6479c9a1713a406c6f5f860e9275d4abf Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 SRPM cifs-utils-7.6-2.el9_8.src.rpm SHA-256: 3f326579ba7916bd17eca5524a1c7f3dbb115a0f71e0e6ebee6fca38ecbc913f ppc64le cifs-utils-7.6-2.el9_8.ppc64le.rpm SHA-256: 3843cc9a942144bd7426f9930f96d85ee5bf2aa28c92200c73d0c92843d055a5 cifs-utils-debuginfo-7.6-2.el9_8.ppc64le.rpm SHA-256: c03d83fcaa371b3e71815cd969244827c53907eb035dafdf222adc64a53eebb9 cifs-utils-debuginfo-7.6-2.el9_8.ppc64le.rpm SHA-256: c03d83fcaa371b3e71815cd969244827c53907eb035dafdf222adc64a53eebb9 cifs-utils-debugsource-7.6-2.el9_8.ppc64le.rpm SHA-256: 83644a188d1456212513a9d05e7faea5eac88e164fd4ada2544b004118f997ec cifs-utils-debugsource-7.6-2.el

Share this article