# CIFSwitch — Linux Kernel CIFS/SPNEGO Key Validation Logic Flaw Enables Unprivileged Local Root via cifs.upcall Namespace Hijack (Public PoC, CVE Pending)

> CIFSwitch is a Linux local privilege escalation disclosed on 2026-05-28 by researcher Asim Manizada, abusing a missing origin check on the kernel's cifs.spnego key type. Any unprivileged process can invoke request_key("cifs.spnego", <forged description>, ...) which causes /sbin/request-key to launch /usr/sbin/cifs.upcall as root with attacker-controlled fields including upcall_target=app and pid=<attacker_pid>; the root upcall switches into the attacker's mount namespace before performing a getpwuid() NSS lookup, executing a malicious libnss_*.so.2 as root and writing an /etc/sudoers.d entry that yields a persistent root shell. The underlying kernel bug has been latent since 2007. Upstream patch 3da1fdf4efbc adds a vet_description hook tying acceptance to the internal spnego_cred. Public PoC is hosted at github.com/manizada/CIFSwitch.

- **Published:** 2026-05-28T00:00:00Z
- **Last reviewed:** 2026-05-28T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0618
- **ID:** TL-2026-0618
- **Severity:** HIGH (CVSS 7.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 16 (full data via the Threadlinqs MCP server — Purple tier)

## Description

## Overview

CIFSwitch (disclosed 2026-05-28) is a Linux local privilege escalation (LPE) chaining a kernel logic flaw in the CIFS subsystem with a privileged upcall behavior in the userspace cifs-utils helper. The vulnerability was discovered by independent researcher Asim Manizada using what he describes as an AI-assisted, multi-hop semantic-graph reasoning approach over kernel security-relevant objects. The kernel-side root cause traces back to 2007, when the cifs.spnego key type was introduced without a `.vet_description` callback to verify that key descriptions originate from inside the CIFS client. CIFSwitch turns this missing origin check into reliable unprivileged-to-root code execution on stock-default installs of many mainstream Linux distributions.

A CVE identifier is pending at time of disclosure. The kernel-side patch (commit 3da1fdf4efbc, "smb: client: reject userspace cifs.spnego descriptions") has been public for over a week and is queued for stable trees. Public PoC and full technical writeup are available at https://github.com/manizada/CIFSwitch and https://heyitsas.im/posts/cifswitch/.

## Exploit Chain

1. **Forged key request (unprivileged):** The attacker process invokes the `request_key(2)` syscall with key type `"cifs.spnego"` and a crafted description string that mimics the format kernel CIFS itself emits, e.g. `ver=0x2;host=<hostname>;ip4=<addr>;sec=krb5;uid=0x0;creduid=0x0;pid=0x<attacker_pid>;upcall_target=app`. Pre-patch, the kernel accepts this description because the cifs_spnego_key_type structure has no `.vet_description` hook, so it cannot tell that the request did not come from inside the CIFS client.
2. **Root upcall (kernel→userspace):** The kernel request_key infrastructure invokes /sbin/request-key, which consults /etc/request-key.d/cifs.spnego.conf (default rule: `create cifs.spnego * * /usr/sbin/cifs.upcall %k`) and spawns /usr/sbin/cifs.upcall as uid 0.
3. **Namespace hijack (uid 0):** cifs.upcall ≥ 6.14 honors the `upcall_target=app` field and uses the `pid=` field to call `switch_to_process_ns()` (setns into the attacker process's namespaces, including mount namespace). The privileged helper is now operating inside the attacker's filesystem view.
4. **NSS code execution as root:** Before dropping privileges, cifs.upcall calls `getpwuid()` to map the supplied uid to a name. NSS resolution reads the attacker-namespace `/etc/nsswitch.conf`, which points at a malicious module loaded via `libnss_<name>.so.2` from the attacker's mount namespace. The shared object's loader is now executing inside uid 0.
5. **Persistence:** Manizada's PoC NSS module writes an /etc/sudoers.d/ entry that grants the unprivileged attacker passwordless root via sudo, providing a stable post-exploit root channel even if the upcall is later sandboxed.

## Pre-Conditions

- Vulnerable kernel (pre-3da1fdf4efbc, effectively every released kernel since 2007 supporting CIFS).
- cifs-utils ≥ 6.14 installed with the default request-key rule for cifs.spnego (older cifs-utils predates the namespace-switching upcall path).
- Unprivileged user/mount namespace creation enabled (`kernel.unprivileged_userns_clone=1` on Debian/Ubuntu derivatives, default-on for upstream).
- No blocking LSM policy — absent or non-confining SELinux/AppArmor for cifs.upcall's setns and dlopen paths.

## Affected Distributions

**Stock-default exploitable (no extra package install required):** Linux Mint Cinnamon 21.3 and 22.3, CentOS Stream 9 GNOME, Rocky Linux 9 Workstation, Kali Linux 2021.4–2026.1 (headless and desktop), AlmaLinux 9.7 Workstation and Azure images, SUSE Linux Enterprise Server 15 SP7 / SLES for SAP 15 SP7 / SLES 16 SP-equivalent.

**Exploitable when cifs-utils is installed (very common in fileserver/admin workstations):** Ubuntu 18.04, 20.04, 22.04, 24.04; Debian 11, 12, 13; Pop!_OS 22.04 and 24.04; Rocky Linux 8; Oracle Linux 8 and 9; openSUSE Leap and Tumbleweed; Amazon Linux 2023.

**Blocked by default policy (LSM, sysctl, or missing namespace switch support):** Ubuntu 26.04 (AppArmor profile), Fedora 40–44, CentOS/Rocky Linux 10, openSUSE Tumbleweed/Leap 16.0.

**Unaffected:** Systems with cifs-utils older than 6.9 (pre-namespace-switching upcall era).

## Patch Analysis

Upstream kernel commit 3da1fdf4efbc490041eb4f836bf596201203f8f2 ("smb: client: reject userspace cifs.spnego descriptions") wires a `.vet_description` callback into `cifs_spnego_key_type`. The hook compares `current_cred()` against the CIFS client's internal `spnego_cred` and returns `-EPERM` for any request not made under that credential, which is only ever set when kernel CIFS itself constructs a key. Userspace request_key() callers, regardless of namespace or capability set, cannot satisfy this check, killing the entire upcall vector at the kernel boundary.

## Defensive Posture

Patching the kernel is the durable fix. Pre-patch, defenders should: (a) blacklist the cifs kernel module on hosts that do not need it (`echo blacklist cifs > /etc/modprobe.d/blacklist-cifs.conf`), (b) override /etc/request-key.d/cifs.spnego.conf to a no-op such as `create cifs.spnego * * /usr/sbin/keyctl negate %k 30 %S`, (c) remove cifs-utils on hosts where it is not used, and (d) where feasible disable unprivileged user namespaces (`sysctl -w kernel.unprivileged_userns_clone=0` on Debian/Ubuntu). SELinux/AppArmor profiles that prevent /usr/sbin/cifs.upcall from invoking setns into untrusted target processes or from dlopen()ing libnss modules outside /lib provide secondary containment.

## Detection Opportunities

The combination of an unprivileged request_key(2) for type "cifs.spnego" followed by /sbin/request-key spawning /usr/sbin/cifs.upcall (audit syscall + execve), cifs.upcall calling setns(CLONE_NEWNS) into an unprivileged process, root-context dlopen of libnss_* outside of standard library paths, and writes to /etc/sudoers.d/ by anything other than dpkg/rpm or root admin sessions are all high-fidelity signals.

## MITRE ATT&CK

- T1106 Native API
- T1546 Event Triggered Execution
- T1098 Account Manipulation
- T1068 Exploitation for Privilege Escalation
- T1548 Abuse Elevation Control Mechanism
- T1611 Escape to Host
- T1574.006 Hijack Execution Flow: Dynamic Linker Hijacking
- T1036.005 Match Legitimate Resource Name or Location
- T1070.004 Indicator Removal: File Deletion
- T1556 Modify Authentication Process
- T1082 System Information Discovery
- T1518 Software Discovery

## Sources

- [CIFSwitch: a non-universal Linux local root vulnerability (Asim Manizada, full technical writeup)](https://heyitsas.im/posts/cifswitch/)
- [oss-security — CIFSwitch: Linux kernel/cifs-utils local root via forged cifs.spnego upcall](https://www.openwall.com/lists/oss-security/2026/05/28/2)
- [manizada/CIFSwitch — Public PoC and writeup](https://github.com/manizada/CIFSwitch)
- [Cyber Security News — New Linux CIFSwitch Kernel Vulnerability Allows Attackers to Gain Root Access](https://cybersecuritynews.com/linux-cifswitch-kernel-vulnerability/)
- [Linux kernel commit 3da1fdf4efbc490041eb4f836bf596201203f8f2 — "smb: client: reject userspace cifs.spnego descriptions"](https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3da1fdf4efbc490041eb4f836bf596201203f8f2)
- [Linux kernel documentation — request_key(2) and key types (background)](https://www.kernel.org/doc/html/latest/security/keys/core.html)
- [cifs-utils upstream (Samba)](https://git.samba.org/?p=cifs-utils.git)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0618
