Bug 34315 - cifs-utils new security issue CVE-2025-2312
Summary: cifs-utils new security issue CVE-2025-2312
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2025-05-28 17:06 CEST by Nicolas Salguero
Modified: 2025-06-05 18:27 CEST (History)
3 users (show)

See Also:
Source RPM: cifs-utils-7.0-1.mga9.src.rpm
CVE: CVE-2025-2312
Status comment:


Attachments

Description Nicolas Salguero 2025-05-28 17:06:00 CEST
Ubuntu has issued an advisory on May 27:
https://ubuntu.com/security/notices/USN-7536-1
Nicolas Salguero 2025-05-28 17:06:24 CEST

Source RPM: (none) => cifs-utils-7.0-1.mga9.src.rpm
CVE: (none) => CVE-2025-2312
Status comment: (none) => Patch available from Ubuntu

Comment 1 Lewis Smith 2025-05-30 20:53:19 CEST
Some Ubuntu versions cite v7.0.2 as the fix. We have 7.2 in Cauldron, OK.
Quite unable to find the patch following everything from the URL in comment 0.
Assigning globally, no fixed maintainer for this.

Assignee: bugsquad => pkg-bugs

Comment 2 Nicolas Salguero 2025-06-03 14:47:07 CEST
Suggested advisory:
========================

The updated packages fix a security vulnerability:

cifs.upcall makes an upcall to the wrong namespace in containerized environments. (CVE-2025-2312)

References:
https://ubuntu.com/security/notices/USN-7536-1
========================

Updated packages in core/updates_testing:
========================
cifs-utils-7.0-1.1.mga9
cifs-utils-devel-7.0-1.1.mga9

from SRPM:
cifs-utils-7.0-1.1.mga9.src.rpm

Status: NEW => ASSIGNED
Assignee: pkg-bugs => qa-bugs
Status comment: Patch available from Ubuntu => (none)

katnatek 2025-06-04 01:13:31 CEST

Keywords: (none) => advisory

Comment 3 Herman Viaene 2025-06-04 16:33:36 CEST
MGA9-64 Plasma Wayland on Compaq H000SB
No installation issues.
ref bug 30360 for testing
# mount.cifs //mach1/beelden /mnt/cifstest/ -o domain=WORKGROUP -o username=herman
Password for herman@//mach1/beelden: 
# ls -als /mnt/cifstest/
total 1032
  0 drwxr-xr-x 2 root root      0 Nov 29  2024 ./
  4 drwxr-xr-x 6 root root   4096 Jun  4 16:29 ../
  0 drwxr-xr-x 2 root root      0 Jul 27  2020 accessbasis/
  0 drwxr-xr-x 2 root root      0 Jul 27  2020 accessfinesses/
  0 drwxr-xr-x 2 root root      0 May  9 13:34 Afbeeldingen/
  0 drwxr-xr-x 2 root root      0 Feb 27  2023 fotos/
820 -rwxr-xr-x 1 root root 838418 Mar 20  2018 Huishouden*
  0 drwxr-xr-x 2 root root      0 Aug 23  2021 lost+found/
  0 drwxr-xr-x 2 root root      0 Jan 12  2019 RawORF/
208 -rwxr-xr-x 1 root root 209872 Jan  6  2019 report.bug.xz*
  0 drwxr-xr-x 2 root root      0 Nov 16  2016 rietmach2/
OK for me.

CC: (none) => herman.viaene
Whiteboard: (none) => MGA9-64-OK

Comment 4 Thomas Andrews 2025-06-05 03:06:20 CEST
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Comment 5 Mageia Robot 2025-06-05 18:27:25 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2025-0176.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.