CIFSwitch Linux Flaw Gives Root Privileges on Multiple Distributions
TL;DR. A new local privilege escalation bug called 'CIFSwitch' in the Linux kernel allows attackers to gain root access on various distributions by forging authentication keys. - The flaw affects Linux distributions running specific versions of the kernel CIFS and cifs-utils. - Attackers can exploit the kernel's key request mechanism to load malicious modules and achieve root code execution. - The vulnerability, introduced in 2007, requires specific conditions and vulnerable software configurations to be exploited.
- CIFSwitch is a local privilege escalation vulnerability found in the Linux kernel's CIFS subsystem.
- The flaw allows unprivileged users to forge cifs.spnego requests, tricking the kernel into running attacker-controlled code as root.
- The researcher confirmed several distributions are vulnerable, including Linux Mint, CentOS Stream, Rocky Linux, and Kali Linux.
Sources
- New CIFSwitch Linux flaw gives root on multiple distributions — bleepingcomputer.com