Permissions, Privileges, and Access Controls in smb4k - CVE-2025-66003
Published: January 2, 2026 / Updated: January 12, 2026
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to application allows arbitrary mounts to be created within the Smb4KMountHelper::mount() function in smb4kmounthelper.cpp. A local user with ability to control content of a Samba network share can mount it over an existing local directory (e.g. /bin) and execute arbitrary code with root privileges.
Affected software
Debian Linux
Fedora
smb4k (Debian package)
smb4k
How to mitigate CVE-2025-66003
smb4k (Debian package) - update to 4.0.0-1+deb13u1
smb4k - addressed in versions 4.0.6-1.fc42, 4.0.6-1.fc43