Security News

Cybersecurity news aggregator

🔓
HIGH Vulnerabilities Ubuntu Security

USN-8496-3: cifs-utils vulnerability

A local privilege escalation vulnerability (CVE-2026-12505, CVSS 7.8 HIGH) in cifs-utils allows a local attacker to execute arbitrary code as root due to the package incorrectly dropping privileges before user lookup. Affected Ubuntu LTS releases require updates to specific package versions: 26.04 LTS to `2:7.4-1ubuntu0.26.04.3`, 24.04 LTS to `2:7.0-2ubuntu0.5`, and 22.04 LTS to `2:6.14-1ubuntu0.6`. This update reintroduces the security fix after a previous regression.
Read Full Article →

Ubuntu Security Notices USN-8496-3 USN-8496-3: cifs-utils vulnerability Publication date 13 July 2026 Overview cifs-utils could be made to run programs as an administrator. Releases 26.04 LTS 24.04 LTS 22.04 LTS Open side navigation Close side navigation Packages Details Update instructions References Related notices Packages cifs-utils - Common Internet File System utilities Details USN-8496-1 fixed vulnerabilities in cifs-utils. The update caused a regression and was backed out in USN-8496-2. This update reintroduces the security fix, along with a fix for the regression. Original advisory details: It was discovered that cifs-utils incorrectly dropped root privileges before looking up user information. A local attacker could possibly use this issue to execute arbitrary code as the root user. USN-8496-1 fixed vulnerabilities in cifs-utils. The update caused a regression and was backed out in USN-8496-2. This update reintroduces the security fix, along with a fix for the regression. Original advisory details: It was discovered that cifs-utils incorrectly dropped root privileges before looking up user information. A local attacker could possibly use this issue to execute arbitrary code as the root user. Update instructions In general, a standard system update will make all the necessary changes. Learn more about how to get the fixes. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 26.04 LTS resolute cifs-utils – 2:7.4-1ubuntu0.26.04.3 24.04 LTS noble cifs-utils – 2:7.0-2ubuntu0.5 22.04 LTS jammy cifs-utils – 2:6.14-1ubuntu0.6 Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References CVE-2026-12505 CVE-2026-12505 Related notices USN-8496-1 USN-8496-1

Share this article