Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.kernel > #86950
| Path | csiph.com!weretis.net!feeder8.news.weretis.net!news.samoylyk.net!gothmog.csi.it!bofh.it!news.nic.it!robomod |
|---|---|
| From | Noah Meyerhans <noahm@debian.org> |
| Newsgroups | linux.debian.kernel |
| Subject | CVE-2025-2312 in cifs-utils |
| Date | Tue, 22 Apr 2025 19:50:02 +0200 |
| Message-ID | <KEpUS-fsNT-9@gated-at.bofh.it> (permalink) |
| X-Original-To | team@security.debian.org, debian-kernel@lists.debian.org, mjt@debian.org |
| X-Mailbox-Line | From debian-kernel-request@lists.debian.org Tue Apr 22 17:49:59 2025 |
| Old-Return-Path | <noahm@debian.org> |
| X-Amavis-Spam-Status | No, score=-110.947 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, DKIMWL_WL_HIGH=-0.438, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, LDO_WHITELIST=-5, MD5_SHA1_SUM=-1, RCVD_IN_DNSWL_MED=-2.3, UNPARSEABLE_RELAY=0.001, USER_IN_DKIM_WELCOMELIST=-0.01, USER_IN_DKIM_WHITELIST=-100] autolearn=ham autolearn_force=no |
| MIME-Version | 1.0 |
| Content-Type | text/plain; charset=us-ascii |
| Content-Disposition | inline |
| X-Debian-User | noahm |
| X-Mailing-List | <debian-kernel@lists.debian.org> archive/latest/148305 |
| List-ID | <debian-kernel.lists.debian.org> |
| List-URL | <https://lists.debian.org/debian-kernel/> |
| List-Archive | https://lists.debian.org/msgid-search/aAfWs0qTLPO3H-oB@doom.morgul.net |
| Approved | robomod@news.nic.it |
| Lines | 26 |
| Organization | linux.* mail to news gateway |
| Sender | robomod@news.nic.it |
| X-Original-Date | Tue, 22 Apr 2025 13:49:39 -0400 |
| X-Original-Message-ID | <aAfWs0qTLPO3H-oB@doom.morgul.net> |
| Xref | csiph.com linux.debian.kernel:86950 |
Show key headers only | View raw
My employer is interested in seeing cifs-utils CVE-2025-2312 (cifs.upcall program from the cifs-utils package makes an upcall to the wrong namespace in containerized environments) fixed in bookworm. [1] According to the tracker, the fix depends on a kernel change in addition to the cifs-utils userspace fix [2, 3]. The kernel change doesn't appear to have been backported to any of the kernel.org LTS trees, so I've suggested that the people responsible for implementation of that change should also work to backport it there. Without this, it seems that even trixie will be vulnerable. I don't believe that this issue warrants a DSA, or that it should be considered RC for trixie. If we publish a fix, it should be by way of a point release containing a kernel that includes the upstream change and an updated cifs-utils package. Do the maintainers involved agree? In the event that upstream is unwilling to apply this change to the kernel LTS trees, would the kernel team consider carrying it as a local patch? Thanks noah 1. https://security-tracker.debian.org/tracker/CVE-2025-2312 2. https://git.kernel.org/linus/db363b0a1d9e6b9dc556296f1b1007aeb496a8cf 3. https://git.samba.org/?p=cifs-utils.git;a=commit;h=89b679228cc1be9739d54203d28289b03352c174
Back to linux.debian.kernel | Previous | Next — Next in thread | Find similar | Unroll thread
CVE-2025-2312 in cifs-utils Noah Meyerhans <noahm@debian.org> - 2025-04-22 19:50 +0200
Re: CVE-2025-2312 in cifs-utils Salvatore Bonaccorso <carnil@debian.org> - 2025-04-22 20:00 +0200
Re: CVE-2025-2312 in cifs-utils Noah Meyerhans <noahm@debian.org> - 2025-04-22 20:20 +0200
Re: CVE-2025-2312 in cifs-utils Salvatore Bonaccorso <carnil@debian.org> - 2025-04-22 21:10 +0200
Re: CVE-2025-2312 in cifs-utils Salvatore Bonaccorso <carnil@debian.org> - 2025-05-20 10:30 +0200
csiph-web