Linux Kernel Vulnerability Grants Root Access for 19 Years

TL;DR. A 19-year-old Linux kernel vulnerability in the CIFS subsystem allows low-privileged users to achieve root access on affected systems. - The CIFSwitch flaw permits attackers to modify key description fields, bypassing origin checks during authentication. - The exploit leverages the cifs-utils helper to load attacker-controlled code as root through a fake NSS config. - Several Linux distributions including CentOS and Kali are vulnerable if cifs-utils is installed by default.

Sources

Back to QLANKR News