Improper Privilege Management in cifs-utils - CVE-2021-20208
Published: June 2, 2022
Vulnerability identifier: #VU63954
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-20208
CWE-ID: CWE-269
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to improper privilege management in cifs-utils. A local user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host.
Affected software
cifs-utils
SUSE Linux Enterprise Server
SUSE Linux Enterprise Software Development Kit
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Server for SAP
openEuler
Fedora
cifs-utils (Ubuntu package)
cifs-utils-debugsource
cifs-utils-devel
cifs-utils-debuginfo
cifs-utils
cifs-utils-help
SUSE Linux Enterprise Server
SUSE Linux Enterprise Software Development Kit
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Server for SAP
openEuler
Fedora
cifs-utils (Ubuntu package)
cifs-utils-debugsource
cifs-utils-devel
cifs-utils-debuginfo
cifs-utils
cifs-utils-help
How to mitigate CVE-2021-20208
Install updates from vendor's website.
cifs-utils - update to 6.13
cifs-utils (Ubuntu package) - addressed in versions 2:6.0-1ubuntu2+esm1, 2:6.4-1ubuntu1.1+esm1, 2:6.8-1ubuntu1.2, 2:6.9-1ubuntu0.2, 2:6.11-3.1ubuntu0.1, 2:6.14-1ubuntu0.1
cifs-utils-debugsource - addressed in versions 6.9-3.14.1, 6.9-5.9.1, 6.9-13.14.1
cifs-utils-devel - addressed in versions 6.9-3.14.1, 6.9-5.9.1, 6.9-13.14.1
cifs-utils-debuginfo - addressed in versions 6.9-3.14.1, 6.9-5.9.1, 6.9-13.14.1
cifs-utils - addressed in versions 6.9-3.14.1, 6.9-5.9.1, 6.9-13.14.1
cifs-utils-debuginfo - update to 6.10-2
cifs-utils-help - update to 6.10-2
cifs-utils-debugsource - update to 6.10-2
cifs-utils-devel - update to 6.10-2
cifs-utils - update to 6.10-2
cifs-utils - addressed in versions 6.13-1.fc33, 6.13-1.fc34, 6.13-1.fc35, 6.13-3.fc33, 6.13-3.fc34, 6.13-3.fc35
cifs-utils (Ubuntu package) - addressed in versions 2:6.0-1ubuntu2+esm1, 2:6.4-1ubuntu1.1+esm1, 2:6.8-1ubuntu1.2, 2:6.9-1ubuntu0.2, 2:6.11-3.1ubuntu0.1, 2:6.14-1ubuntu0.1
cifs-utils-debugsource - addressed in versions 6.9-3.14.1, 6.9-5.9.1, 6.9-13.14.1
cifs-utils-devel - addressed in versions 6.9-3.14.1, 6.9-5.9.1, 6.9-13.14.1
cifs-utils-debuginfo - addressed in versions 6.9-3.14.1, 6.9-5.9.1, 6.9-13.14.1
cifs-utils - addressed in versions 6.9-3.14.1, 6.9-5.9.1, 6.9-13.14.1
cifs-utils-debuginfo - update to 6.10-2
cifs-utils-help - update to 6.10-2
cifs-utils-debugsource - update to 6.10-2
cifs-utils-devel - update to 6.10-2
cifs-utils - update to 6.10-2
cifs-utils - addressed in versions 6.13-1.fc33, 6.13-1.fc34, 6.13-1.fc35, 6.13-3.fc33, 6.13-3.fc34, 6.13-3.fc35
External References
- https://bugzilla.samba.org/show_bug.cgi?id=14651
- https://bugzilla.redhat.com/show_bug.cgi?id=1921116
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Z4BZSJXROEFHYATAAHHRR6P3HUSMPQB3/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2W4HSDIWXXNQBUW5ZS37RQMLJ7THK5AS/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/66WJ3SVBHCSNQZAWSGLB6FBOCFU45FFG/
Related Security Bulletins
- Privilege escalation in cifs-utils
- Ubuntu update for cifs-utils
- SUSE update for cifs-utils
- SUSE update for cifs-utils
- SUSE update for cifs-utils
- openEuler 20.03 LTS SP1 update for cifs-utils
- Fedora 35 update for cifs-utils
- Fedora 34 update for cifs-utils
- Fedora 33 update for cifs-utils
- Fedora 35 update for cifs-utils
- Fedora 34 update for cifs-utils
- Fedora 33 update for cifs-utils
- Ubuntu update for cifs-utils