Red Hat Product Errata RHSA-2026:39575 - Security Advisory Issued: 2026-07-15 Updated: 2026-07-15 RHSA-2026:39575 - Security Advisory Overview Updated Packages Synopsis Important: cifs-utils security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for cifs-utils is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The SMB/CIFS protocol is a standard file sharing protocol widely deployed on Microsoft Windows machines. The cifs-utils packages contain tools for mounting shares on Linux using the SMB/CIFS protocol. The tools in this package work in conjunction with support in the kernel to allow one to mount a SMB/CIFS share onto a client and use it as if it were a standard Linux file system. Security Fix(es): cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall (CVE-2026-12505) Bug Fix(es) and Enhancement(s): add sssd method for mapping SID to UID/GID in man page of mount.cifs [rhel-8.10.z] (JIRA:RHEL-41059) Update the mount.cifs man page to match the 3*echo_interval reconnection timeout (JIRA:RHEL-80397) cifs-utils: regression with kerberos mount [rhel-8.10.z] (JIRA:RHEL-192933) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Enterprise Linux for IBM z Systems 8 s390x Red Hat Enterprise Linux for Power, little endian 8 ppc64le Red Hat Enterprise Linux for ARM 64 8 aarch64 Red Hat CodeReady Linux Builder for x86_64 8 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 8 ppc64le Red Hat CodeReady Linux Builder for ARM 64 8 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x Fixes BZ - 2489805 - CVE-2026-12505 cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall RHEL-80397 - Update the mount.cifs man page to match the 3*echo_interval reconnection timeout CVEs CVE-2026-12505 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 8 SRPM cifs-utils-7.0-5.el8_10.src.rpm SHA-256: 45bef8e4b40d246a37a28489b248ea8a3102057a37bb71e4b0bd7997456840d1 x86_64 cifs-utils-7.0-5.el8_10.x86_64.rpm SHA-256: 80a084308cd646be855c4dc839138e182ce35b9ea83fbde6e1945e02b8ce853a cifs-utils-debuginfo-7.0-5.el8_10.x86_64.rpm SHA-256: 133ce0ebdc8dbc811d0526a997d92285160185dff72be812de6bc162a70c0f54 cifs-utils-debugsource-7.0-5.el8_10.x86_64.rpm SHA-256: 27d11b7cb2fa26dc3bc2c8816692a0ee99aa348c436a06967aba1879fa37205c pam_cifscreds-7.0-5.el8_10.x86_64.rpm SHA-256: e2fd813609aa54b065580227e80aa10154b222d731a9fedb1254503b0b07ce6d pam_cifscreds-debuginfo-7.0-5.el8_10.x86_64.rpm SHA-256: 2b5ac2d8bb6676f8fb5b84cb9c6303e15636ce2a78600115d2136c1434104273 Red Hat Enterprise Linux for IBM z Systems 8 SRPM cifs-utils-7.0-5.el8_10.src.rpm SHA-256: 45bef8e4b40d246a37a28489b248ea8a3102057a37bb71e4b0bd7997456840d1 s390x cifs-utils-7.0-5.el8_10.s390x.rpm SHA-256: 9da5811d75097ab5c2ec4ee4346b5979fba7e75d23e069996d49962e7fd6ca20 cifs-utils-debuginfo-7.0-5.el8_10.s390x.rpm SHA-256: 9e84368dfe4e4d51b24dc7d7c642010c2cb2171872fb341f976c715bc4382674 cifs-utils-debugsource-7.0-5.el8_10.s390x.rpm SHA-256: a686631074ce23c4952243bc66832ee6b07b37fdefed68c2f6e010dfed37903f pam_cifscreds-7.0-5.el8_10.s390x.rpm SHA-256: 51feaee8bfc939684cfef47ed69067e5848439e57842cf7a94bf81fabbe8d90c pam_cifscreds-debuginfo-7.0-5.el8_10.s390x.rpm SHA-256: 5413b9965dd436af8f20a6ed4fc4793226cc42e1716335f8ae01f9747b41f459 Red Hat Enterprise Linux for Power, little endian 8 SRPM cifs-utils-7.0-5.el8_10.src.rpm SHA-256: 45bef8e4b40d246a37a28489b248ea8a3102057a37bb71e4b0bd7997456840d1 ppc64le cifs-utils-7.0-5.el8_10.ppc64le.rpm SHA-256: a46876cb5a8f57c7ee0d043c26043d5ed71a4c8aa0b75d45c31cf056f60657ff cifs-utils-debuginfo-7.0-5.el8_10.ppc64le.rpm SHA-256: 90408ac0dd3701e1401aea3c83ad55e6cb5672babdaf931c2b765072a283bfd0 cifs-utils-debugsource-7.0-5.el8_10.ppc64le.rpm SHA-256: a2b25f9e39c3c321afd3102480fa4ff100b3b353c8de8c414bc5787ff7145959 pam_cifscreds-7.0-5.el8_10.ppc64le.rpm SHA-256: 132257d80b3c87bdb9797c0a7105974b6d7e20ae65187a76f2704f1508d9919f pam_cifscreds-debuginfo-7.0-5.el8_10.ppc64le.rpm SHA-256: c8e034e1f22a8a64a6232b6364aea35d57fe8175fff4d3b1ccf655cfb8059f90 Red Hat Enterprise Linux for ARM 64 8 SRPM cifs-utils-7.0-5.el8_10.src.rpm SHA-256: 45bef8e4b40d246a37a28489b248ea8a3102057a37bb71e4b0bd7997456840d1 aarch64 cifs-utils-7.0-5.el8_10.aarch64.rpm SHA-256: 32ebf352c26f8284b8e72713346e5a75e367d5285850583d000d83827e70be7d cifs-utils-debuginfo-7.0-5.el8_10.aarch64.rpm SHA-256: dc2a1c2825be25caa08085e407ed1d799f89b9011fc416a7d0cdb2533d27569f cifs-utils-debugsource-7.0-5.el8_10.aarch64.rpm SHA-256: ff3daeb207338472c40cf5ddff2a14fc64d64ecae0f416330512dbf207c71061 pam_cifscreds-7.0-5.el8_10.aarch64.rpm SHA-256: b1c055039620645cd1df5317f2feeaeb529501923c53ec060e2358a9aa17e4ef pam_cifscreds-debuginfo-7.0-5.el8_10.aarch64.rpm SHA-256: 767264fa7355f9e9c0f868c4c47b51bd6bd9ba2c530d08eec1f65f3238b5cf1e Red Hat CodeReady Linux Builder for x86_64 8 SRPM x86_64 cifs-utils-debuginfo-7.0-5.el8_10.i686.rpm SHA-256: a131a33bd0912b6dac0eeba32f56ea6abedc3bbfe4ba7215464b6af2a3773f55 cifs-utils-debuginfo-7.0-5.el8_10.x86_64.rpm SHA-256: 133ce0ebdc8dbc811d0526a997d92285160185dff72be812de6bc162a70c0f54 cifs-utils-debugsource-7.0-5.el8_10.i686.rpm SHA-256: 5ce82d298595d73a79f0f465e88b7566c019c959b5aa33146d39ab60c7888d7b cifs-utils-debugsource-7.0-5.el8_10.x86_64.rpm SHA-256: 27d11b7cb2fa26dc3bc2c8816692a0ee99aa348c436a06967aba1879fa37205c cifs-utils-devel-7.0-5.el8_10.i686.rpm SHA-256: 67d0b1b8604879b98e7a79ac30ff164ce9d216c0bc8729204bb1723de91dd062 cifs-utils-devel-7.0-5.el8_10.x86_64.rpm SHA-256: eb1d2d80ecd8fdeb6df428e43de3104410d597bf056c0fe944e21d98677821f1 pam_cifscreds-debuginfo-7.0-5.el8_10.i686.rpm SHA-256: f34bf399276eb8d5ec85afd91aa9d15205b8f4796f5b5df719ab05cb22f102d1 pam_cifscreds-debuginfo-7.0-5.el8_10.x86_64.rpm SHA-256: 2b5ac2d8bb6676f8fb5b84cb9c6303e15636ce2a78600115d2136c1434104273 Red Hat CodeReady Linux Builder for Power, little endian 8 SRPM ppc64le cifs-utils-debuginfo-7.0-5.el8_10.ppc64le.rpm SHA-256: 90408ac0dd3701e1401aea3c83ad55e6cb5672babdaf931c2b765072a283bfd0 cifs-utils-debugsource-7.0-5.el8_10.ppc64le.rpm SHA-256: a2b25f9e39c3c321afd3102480fa4ff100b3b353c8de8c414bc5787ff7145959 cifs-utils-devel-7.0-5.el8_10.ppc64le.rpm SHA-256: 756e1d93c61a51b65dc1000036fcfd5ad079f987b9f0a2ff53483c380b13d0ea pam_cifscreds-debuginfo-7.0-5.el8_10.ppc64le.rpm SHA-256: c8e034e1f22a8a64a6232b6364aea35d57fe8175fff4d3b1ccf655cfb8059f90 Red Hat CodeReady Linux Builder for ARM 64 8 SRPM aarch64 cifs-utils-debuginfo-7.0-5.el8_10.aarch64.rpm SHA-256: dc2a1c2825be25caa08085e407ed1d799f89b9011fc416a7d0cdb2533d27569f cifs-utils-debugsource-7.0-5.el8_10.aarch64.rpm SHA-256: ff3daeb207338472c40cf5ddff2a14fc64d64ecae0f416330512dbf207c71061 cifs-utils-devel-7.0-5.el8_10.aarch64.rpm SHA-256: 9ed22407418e28718b85d2d54e83cee44232034c5f67d7617111c961b6027726 pam_cifscreds-debuginfo-7.0-5.el8_10.aarch64.rpm SHA-256: 767264fa7355f9e9c0f868c4c47b51bd6bd9ba2c530d08eec1f65f3238b5cf1e Red Hat CodeReady Linux Builder for IBM z Systems 8 SRPM s390x cifs-utils-debuginfo-7.0-5.el8_10.s390x.rpm SHA-256: 9e84368dfe4e4d51b24dc7d7c642010c2cb2171872fb341f976c715bc4382674 cifs-utils-debugsource-7.0-5.el8_10.s390x.rpm SHA-256: a686631074ce23c4952243bc66832ee6b07b37fdefed68c2f6e010dfed37903f cifs-utils-devel-7.0-5.el8_10.s390x.rpm SHA-256: 05bc9ab79128b195d7d79cad4ec9181e340d69074f240895e4eab31a34736cb8 pam_cifscreds-debuginfo-7.0-5.el8_10.s390x.rpm SHA-256: 5413b9965dd436af8f20a6ed4fc4793226cc42e1716335f8ae01f9747b41f459 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 SRPM cifs-utils-7.0-5.el8_10.src.rpm SHA-256: 45bef8e4b40d246a37a28489b248ea8a3102057a37bb71e4b0bd7997456840d1 x86_64 cifs-utils-7.0-5.el8_10.x86_64.rpm SHA-256: 80a084308cd646be855c4dc839138e182ce35b9ea83fbde6e1945e02b8ce853a cifs-utils-debuginfo-7.0-5.el8_10.x86_64.rpm SHA-256: 133ce0ebdc8dbc811d0526a997d92285160185dff72be812de6bc162a70c0f54 cifs-utils-debugsource-7.0-5.el8_10.x86_64.rpm SHA-256: 27d11b7cb2fa26dc3bc2c8816692a0ee99aa348c436a06967aba1879fa37205c pam_cifscreds-7.0-5.el8_10.x86_64.rpm SHA-256: e2fd813609aa54b065580227e80aa10154b222d731a9fedb1254503b0b07ce6d pam_cifscreds-debuginfo-7.0-5.el8_10.x86_64.rpm SHA-256: 2b5ac2d8bb6676f8fb5b84cb9c6303e15636ce2a78600115d2136c1434104273 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 SRPM cifs-utils-7.0-5.el8_10.src.rpm SHA-256: 45bef8e4b40d246a37a28489b248ea8a3102057a37bb71e4b0bd7997456840d1 aarch64 cifs-utils-7.0-5.el8_10.aarch64.rpm SHA-256: 32ebf352c26f8284b8e72713346e5a75e367d5285850583d000d83827e70be7d cifs-utils-debuginfo-7.0-5.el8_10.aarch64.rpm SHA-256: dc2a1c2825be25caa08085e407ed1d799f89b9011fc416a7d0cdb2533d27569f cifs-utils-debugsource-7.0-5.el8_10.aarch64.rpm SHA-256: ff3daeb207338472c40cf5ddff2a14fc64d64ecae0f416330512dbf207c71
This update addresses CVE-2026-12505 (CVSS 7.8 High), a local privilege escalation vulnerability in cifs-utils where an attacker can forge a cifs.spnego key description in the cifs.upcall process. The advisory is rated Important and applies to Red Hat Enterprise Linux 8 systems; specific affected and fixed version numbers for the cifs-utils package are not provided in the source text. Administrators should apply the referenced Red Hat update to their affected RHEL 8 deployments.