Monday, June 16, 2025

[USN-7536-2] cifs-utils regression

-----BEGIN PGP SIGNATURE-----

wsF5BAABCAAjFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmhQJKMFAwAAAAAACgkQZWnYVadEvpNd
MQ/+KSxtPpbdF9Azfu3e+bGUUx64ujT06WkUl2kMufDLnS3Bs3iSRYkSzTiCqe+RN6UKwj1fhkNX
ZeLYqLIdsUrgo0170DneUeOc8Ff8RioBa5CQBt53a/RpTRSchwi4SotCOPlJrLaQsFKqpbWeo/H2
hBalcoZTqqsFAd1WqTEMeKCOqguGzEN9MDo40hCDtcyomHbG22Y8JvIE+dt/mYSFCsuHonhoX/Es
JTreKAjL1CPFuYfT2n/Q2ae7Rn1lt1D6DLCOsWhptrcM1+GXRWtKX52SVVMcp47durjsnNC11mIw
jUQIFydpspo/3ODVa09JaYiLdrzNHAFZhgZ887+x1/3aKSMMPvg4rGA9mDPFnhbfktF45BCQxEbB
3fxPBqsnDDFQnLe6xP4lXhe7343v/w2E+cRrztQneF3wsz8SXQ0iTepe/Eb/vb+/JDjZBXKZUdfV
7ZBxaVtTvC6FEAsYApJwdN9EvMwxYtZRWwGUJ0qM+kKoxqCYQ6b12NCORk639oFj1+O9EwyurIun
AnKVLhbnozX7eAuSQ/oYbr18I0eAZZWOVQ7b5iK045Ce3nW8qXOm4Gjn0IhdytLFY5GZUhNrAO7B
EtH45VLb57IqzEzwj9Yji9KPnVTeU6CZNn966lbln+X60R3+Xiey6JkNv4agSkBHlD/0dB44JtzW
FsQ=
=LtXd
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7536-2
June 16, 2025

cifs-utils regression
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 25.04
- Ubuntu 24.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS

Summary:

USN-7536-1 introduced a regression in cifs-utils.

Software Description:
- cifs-utils: Common Internet File System utilities

Details:

USN-7536-1 fixed vulnerabilities in cifs-utils. This update introduced a
regression in certain environments. This update fixes the problem.

We apologize for the inconvenience.

Original advisory details:

It was discovered that cifs-utils incorrectly handled namespaces when
obtaining Kerberos credentials. An attacker could possibly use this issue
to obtain sensitive information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 25.04
cifs-utils 2:7.2-2ubuntu0.1

Ubuntu 24.10
cifs-utils 2:7.0-2.1ubuntu0.2

Ubuntu 24.04 LTS
cifs-utils 2:7.0-2ubuntu0.2

Ubuntu 22.04 LTS
cifs-utils 2:6.14-1ubuntu0.3

Ubuntu 20.04 LTS
cifs-utils 2:6.9-1ubuntu0.4

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-7536-2
https://ubuntu.com/security/notices/USN-7536-1
https://launchpad.net/bugs/2112614, https://launchpad.net/bugs/2113906

Package Information:
https://launchpad.net/ubuntu/+source/cifs-utils/2:7.2-2ubuntu0.1
https://launchpad.net/ubuntu/+source/cifs-utils/2:7.0-2.1ubuntu0.2
https://launchpad.net/ubuntu/+source/cifs-utils/2:7.0-2ubuntu0.2
https://launchpad.net/ubuntu/+source/cifs-utils/2:6.14-1ubuntu0.3
https://launchpad.net/ubuntu/+source/cifs-utils/2:6.9-1ubuntu0.4

No comments:

Post a Comment