Threat reportVulnerabilityTL-2026-0618

CIFSwitch — Linux Kernel CIFS/SPNEGO Key Validation Logic Flaw Enables Unprivileged Local Root via cifs.upcall Namespace Hijack (Public PoC, CVE Pending)

highACTIVE

CIFSwitch — Linux Kernel CIFS/SPNEGO Key Validation Logic (TL-2026-0618), also tracked as CIFSwitch, is a high-severity software vulnerability scored CVSS 7.8, first published 2026-05-28. It has no confirmed attribution, affects Linux Kernel Linux kernel CIFS client (fs/smb/client, fs/cifs), maps to 12 MITRE ATT&CK techniques (T1036.005, T1068, T1070.004), and is covered by 9 detection rules and 16 indicators of compromise.

CVSS
7.8/10High
CVEs
0None referenced
Techniques
12MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
16Indicators of compromise

Key facts for TL-2026-0618

Threat ID
TL-2026-0618
Also known as
CIFSwitch
Severity
HIGH
CVSS
7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
government, defense, financial, technology, telecommunications, education, healthcare, managed-service-providers, cloud-hosting, research
Target regions
Global, North America, Europe, Asia-Pacific, Middle East, Latin America
Detection rules
9
Indicators of compromise
16

Malware and tooling in CIFSwitch — Linux Kernel CIFS/SPNEGO Key Validation Logic

Malware and tooling: CIFSwitch PoC (github.com/manizada/CIFSwitch)

How CIFSwitch — Linux Kernel CIFS/SPNEGO Key Validation Logic works

CIFSwitch is a Linux local privilege escalation disclosed on 2026-05-28 by researcher Asim Manizada, abusing a missing origin check on the kernel's cifs.spnego key type. Any unprivileged process can invoke request_key("cifs.spnego", <forged description>, ...) which causes /sbin/request-key to launch /usr/sbin/cifs.upcall as root with attacker-controlled fields including upcall_target=app and pid=<attacker_pid>; the root upcall switches into the attacker's mount namespace before performing a getpwuid() NSS lookup, executing a malicious libnss_*.so.2 as root and writing an /etc/sudoers.d entry that yields a persistent root shell. The underlying kernel bug has been latent since 2007. Upstream patch 3da1fdf4efbc adds a vet_description hook tying acceptance to the internal spnego_cred. Public PoC is hosted at github.com/manizada/CIFSwitch.

## Overview

CIFSwitch (disclosed 2026-05-28) is a Linux local privilege escalation (LPE) chaining a kernel logic flaw in the CIFS subsystem with a privileged upcall behavior in the userspace cifs-utils helper. The vulnerability was discovered by independent researcher Asim Manizada using what he describes as an AI-assisted, multi-hop semantic-graph reasoning approach over kernel security-relevant objects. The kernel-side root cause traces back to 2007, when the cifs.spnego key type was introduced without a `.vet_description` callback to verify that key descriptions originate from inside the CIFS client. CIFSwitch turns this missing origin check into reliable unprivileged-to-root code execution on stock-default installs of many mainstream Linux distributions.

A CVE identifier is pending at time of disclosure. The kernel-side patch (commit 3da1fdf4efbc, "smb: client: reject userspace cifs.spnego descriptions") has been public for over a week and is queued for stable trees. Public PoC and full technical writeup are available at https://github.com/manizada/CIFSwitch and https://heyitsas.im/posts/cifswitch/.

## Exploit Chain

1. **Forged key request (unprivileged):** The attacker process invokes the `request_key(2)` syscall with key type `"cifs.spnego"` and a crafted description string that mimics the format kernel CIFS itself emits, e.g. `ver=0x2;host=<hostname>;ip4=<addr>;sec=krb5;uid=0x0;creduid=0x0;pid=0x<attacker_pid>;upcall_target=app`. Pre-patch, the kernel accepts this description because the cifs_spnego_key_type structure has no `.vet_description` hook, so it cannot tell that the request did not come from inside the CIFS client. 2. **Root upcall (kernel→userspace):** The kernel request_key infrastructure invokes /sbin/request-key, which consults /etc/request-key.d/cifs.spnego.conf (default rule: `create cifs.spnego * * /usr/sbin/cifs.upcall %k`) and spawns /usr/sbin/cifs.upcall as uid 0. 3. **Namespace hijack (uid 0):** cifs.upcall ≥ 6.14 honors the `upcall_target=app` field and uses the `pid=` field to call `switch_to_process_ns()` (setns into the attacker process's namespaces, including mount namespace). The privileged helper is now operating inside the attacker's filesystem view. 4. **NSS code execution as root:** Before dropping privileges, cifs.upcall calls `getpwuid()` to map the supplied uid to a name. NSS resolution reads the attacker-namespace `/etc/nsswitch.conf`, which points at a malicious module loaded via `libnss_<name>.so.2` from the attacker's mount namespace. The shared object's loader is now executing inside uid 0. 5. **Persistence:** Manizada's PoC NSS module writes an /etc/sudoers.d/ entry that grants the unprivileged attacker passwordless root via sudo, providing a stable post-exploit root channel even if the upcall is later sandboxed.

## Pre-Conditions

- Vulnerable kernel (pre-3da1fdf4efbc, effectively every released kernel since 2007 supporting CIFS). - cifs-utils ≥ 6.14 installed with the default request-key rule for cifs.spnego (older cifs-utils predates the namespace-switching upcall path). - Unprivileged user/mount namespace creation enabled (`kernel.unprivileged_userns_clone=1` on Debian/Ubuntu derivatives, default-on for upstream). - No blocking LSM policy — absent or non-confining SELinux/AppArmor for cifs.upcall's setns and dlopen paths.

## Affected Distributions

**Stock-default exploitable (no extra package install required):** Linux Mint Cinnamon 21.3 and 22.3, CentOS Stream 9 GNOME, Rocky Linux 9 Workstation, Kali Linux 2021.4–2026.1 (headless and desktop), AlmaLinux 9.7 Workstation and Azure images, SUSE Linux Enterprise Server 15 SP7 / SLES for SAP 15 SP7 / SLES 16 SP-equivalent.

**Exploitable when cifs-utils is installed (very common in fileserver/admin workstations):** Ubuntu 18.04, 20.04, 22.04, 24.04; Debian 11, 12, 13; Pop!_OS 22.04 and 24.04; Rocky Linux 8; Oracle Linux 8 and 9; openSUSE Leap and Tumbleweed; Amazon Linux 2023.

**Blocked by default policy (LSM, sysctl, or missing namespace switch support):** Ubuntu 26.04 (AppArmor profile), Fedora 40–44, CentOS/Rocky Linux 10, openSUSE Tumbleweed/Leap 16.0.

**Unaffected:** Systems with cifs-utils older than 6.9 (pre-namespace-switching upcall era).

## Patch Analysis

Upstream kernel commit 3da1fdf4efbc490041eb4f836bf596201203f8f2 ("smb: client: reject userspace cifs.spnego descriptions") wires a `.vet_description` callback into `cifs_spnego_key_type`. The hook compares `current_cred()` against the CIFS client's internal `spnego_cred` and returns `-EPERM` for any request not made under that credential, which is only ever set when kernel CIFS itself constructs a key. Userspace request_key() callers, regardless of namespace or capability set, cannot satisfy this check, killing the entire upcall vector at the kernel boundary.

## Defensive Posture

Patching the kernel is the durable fix. Pre-patch, defenders should: (a) blacklist the cifs kernel module on hosts that do not need it (`echo blacklist cifs > /etc/modprobe.d/blacklist-cifs.conf`), (b) override /etc/request-key.d/cifs.spnego.conf to a no-op such as `create cifs.spnego * * /usr/sbin/keyctl negate %k 30 %S`, (c) remove cifs-utils on hosts where it is not used, and (d) where feasible disable unprivileged user namespaces (`sysctl -w kernel.unprivileged_userns_clone=0` on Debian/Ubuntu). SELinux/AppArmor profiles that prevent /usr/sbin/cifs.upcall from invoking setns into untrusted target processes or from dlopen()ing libnss modules outside /lib provide secondary containment.

## Detection Opportunities

The combination of an unprivileged request_key(2) for type "cifs.spnego" followed by /sbin/request-key spawning /usr/sbin/cifs.upcall (audit syscall + execve), cifs.upcall calling setns(CLONE_NEWNS) into an unprivileged process, root-context dlopen of libnss_* outside of standard library paths, and writes to /etc/sudoers.d/ by anything other than dpkg/rpm or root admin sessions are all high-fidelity signals.

MITRE ATT&CK techniques used in TL-2026-0618

Defense Evasion

T1036.005 Match Legitimate Resource Name or Location; T1070.004 Indicator Removal: File Deletion; T1574.006 Hijack Execution Flow: Dynamic Linker Hijacking

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism; T1611 Escape to Host

Discovery

T1082 System Information Discovery; T1518 Software Discovery

Persistence

T1098 Account Manipulation; T1546 Event Triggered Execution

Execution

T1106 Native API

defense-impairment

T1556 Modify Authentication Process

Affected products and versions in CIFSwitch — Linux Kernel CIFS/SPNEGO Key Validation Logic

  • Linux Kernel — Linux kernel CIFS client (fs/smb/client, fs/cifs)
    Vulnerable versions: 2.6.x (cifs.spnego key type introduced ~2007) through pre-commit 3da1fdf4efbc
    Fixed in: Mainline with commit 3da1fdf4efbc; stable backports pending per distro
  • Samba Team — cifs-utils
    Vulnerable versions: 6.14 and later (introduced upcall_target=app namespace-switching path)
    Fixed in: No userspace fix required once kernel patch lands; pre-6.9 builds are not exploitable
  • Canonical — Ubuntu
    Vulnerable versions: 18.04 LTS; 20.04 LTS; 22.04 LTS; 24.04 LTS (with cifs-utils installed)
    Fixed in: 26.04 (AppArmor-blocked by default); awaiting USN for older releases
  • Debian — Debian GNU/Linux
    Vulnerable versions: 11 (bullseye); 12 (bookworm); 13 (trixie) — with cifs-utils installed
    Fixed in: Awaiting DSA
  • Red Hat / IBM — Rocky Linux / AlmaLinux / CentOS Stream / Oracle Linux (RHEL family)
    Vulnerable versions: CentOS Stream 9 GNOME (stock); Rocky Linux 9 Workstation (stock); AlmaLinux 9.7 Workstation/Azure (stock); Rocky 8 / Oracle Linux 8 and 9 (with cifs-utils)
    Fixed in: Rocky/CentOS 10 default policy blocks; awaiting RHSA/ELSA
  • SUSE — SUSE Linux Enterprise Server / openSUSE
    Vulnerable versions: SLES 15 SP7; SLES for SAP 15 SP7; SLES 16; openSUSE Leap (with cifs-utils); openSUSE Tumbleweed (with cifs-utils)
    Fixed in: openSUSE Tumbleweed/Leap 16.0 default policy blocks; awaiting SUSE-SU
  • Offensive Security — Kali Linux
    Vulnerable versions: 2021.4 through 2026.1 (headless and desktop, stock)
    Fixed in: Awaiting Kali rolling update
  • Linux Mint — Linux Mint
    Vulnerable versions: Cinnamon 21.3; Cinnamon 22.3
    Fixed in: Awaiting upstream Ubuntu kernel update
  • System76 — Pop!_OS
    Vulnerable versions: 22.04; 24.04 (with cifs-utils)
    Fixed in: Awaiting Ubuntu kernel backport
  • Amazon Web Services — Amazon Linux
    Vulnerable versions: Amazon Linux 2023 (with cifs-utils)
    Fixed in: Awaiting ALAS

Remediation for CIFSwitch — Linux Kernel CIFS/SPNEGO Key Validation Logic

Patches

  • Linux kernel commit 3da1fdf4efbc490041eb4f836bf596201203f8f2 ("smb: client: reject userspace cifs.spnego descriptions") — apply via distro kernel updates as backports become available.
  • Track distro CVE trackers (Ubuntu USN, Debian DSA, Red Hat RHSA, SUSE SUSE-SU, Oracle ELSA, Amazon ALAS) for the pending CVE ID once assigned.

Immediate actions

  • Blacklist the cifs kernel module on hosts that do not mount SMB shares: `echo blacklist cifs > /etc/modprobe.d/blacklist-cifs.conf && update-initramfs -u` (Debian/Ubuntu) or `dracut -f` (RHEL-family).
  • Override the request-key handler for cifs.spnego on unpatched hosts. Replace /etc/request-key.d/cifs.spnego.conf with a negating rule: `create cifs.spnego * * /usr/sbin/keyctl negate %k 30 %S` so the kernel cannot reach /usr/sbin/cifs.upcall.
  • Remove cifs-utils on hosts that do not use SMB shares (`apt purge cifs-utils` / `dnf remove cifs-utils`).
  • On Debian/Ubuntu lineages disable unprivileged user namespaces where feasible: `sysctl -w kernel.unprivileged_userns_clone=0` (will break LXD, snap confinement, Chrome sandbox, etc., so stage carefully).
  • Inventory hosts running cifs-utils ≥ 6.14 and any kernel pre-3da1fdf4efbc; treat multi-tenant or shell-accessible Linux servers (jump boxes, build runners, CI workers, shared dev hosts) as highest priority.

Workarounds

  • Negate cifs.spnego upcall in /etc/request-key.d/cifs.spnego.conf.
  • Module blacklist for cifs.ko.
  • Disable unprivileged user namespaces.
  • Remove or restrict cifs-utils package.

Longer-term hardening

  • Apply kernel updates from each distribution as the 3da1fdf4efbc backport lands; track stable trees and major distro security mailing lists.
  • Deploy AppArmor/SELinux profiles that restrict /usr/sbin/cifs.upcall to setns() into kernel-originated targets only and forbid dlopen() of libnss modules outside trusted paths.
  • Stand up audit rules and EDR detections for unprivileged request_key(2) with type "cifs.spnego", root-context dlopen of NSS modules from non-system paths, and unexpected writes to /etc/sudoers.d/.
  • Where business need allows, transition off in-kernel CIFS to userspace SMB clients (gvfs/smbclient) on developer workstations to remove the upcall path entirely.
  • Adopt a default policy of `kernel.unprivileged_userns_clone=0` plus explicit allowlist for workloads that need user namespaces (containers, browser sandboxes).

Weaknesses (CWE) in CIFSwitch — Linux Kernel CIFS/SPNEGO Key Validation Logic

CWE-345, CWE-269, CWE-863, CWE-358

Timeline of CIFSwitch — Linux Kernel CIFS/SPNEGO Key Validation Logic

  • Linux kernel introduces the cifs.spnego key type without a vet_description callback, allowing any caller (kernel or unprivileged userspace) to register key descriptions. This is the latent root cause exploited 19 years later by CIFSwitch.
  • Asim Manizada privately reports CIFSwitch to Linux kernel and CIFS maintainers, beginning embargoed coordination with the linux-distros mailing list.
  • Upstream kernel commit 3da1fdf4efbc ("smb: client: reject userspace cifs.spnego descriptions") lands publicly, adding a vet_description hook tying acceptance to spnego_cred. Patch sits public for over a week before disclosure.
  • Full technical writeup published at https://heyitsas.im/posts/cifswitch/ detailing the exploit chain, affected distributions, and mitigation set.
  • Threadlinqs Intelligence ingests CIFSwitch for tracking under TL-2026-0618. CVP-authorized full-spectrum analysis initiated, including exploit chain mapping, distro impact matrix, and detection engineering.
  • Public disclosure on oss-security (openwall list) and release of weaponized PoC at https://github.com/manizada/CIFSwitch. CVE assignment pending. Cyber Security News covers the disclosure same day.
  • As of 2026-05-29, CIFSwitch remains a live Linux LPE: a weaponized public PoC (github.com/manizada/CIFSwitch) exists and the upstream fix (commit 3da1fdf4efbc) is still rolling out via distro testing repos and KernelCare livepatches, so most hosts stay exploitable. No CVE assigned yet, not in CISA KEV, and no confirmed in-the-wild abuse reported.

Sources cited for CIFSwitch — Linux Kernel CIFS/SPNEGO Key Validation Logic

Detection coverage for TL-2026-0618

As of 2026-05-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0618 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
16 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats