CIFSwitch Linux Flaw Gives Root Privileges on Multiple Distributions

TL;DR. A new local privilege escalation bug called 'CIFSwitch' in the Linux kernel allows attackers to gain root access on various distributions by forging authentication keys. - The flaw affects Linux distributions running specific versions of the kernel CIFS and cifs-utils. - Attackers can exploit the kernel's key request mechanism to load malicious modules and achieve root code execution. - The vulnerability, introduced in 2007, requires specific conditions and vulnerable software configurations to be exploited.

Sources

Back to QLANKR News