https://bugs.kde.org/show_bug.cgi?id=513716

Alexander Reinholdt <[email protected]> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
             Status|REPORTED                    |RESOLVED
         Resolution|---                         |NOT A BUG

--- Comment #1 from Alexander Reinholdt <[email protected]> ---
I am very sorry that the latest version of Smb4K broke your settings and
scripts. However, the change that affected you was introduced on purpose: 

Smb4K underwent a security review by the SUSE security team. They found two
major vulnerabilites in the mount helper (full report:
https://security.opensuse.org/2025/12/10/smb4k-major-issues-in-kauth-helper.html):

CVE-2025-66002: local users can perform arbitrary unmounts via smb4kmounthelper
due to lack of input validation
CVE-2025-66003: local users can perform a local root exploit via smb4k
mounthelper if they can access and control the contents of a Samba share

These were fixed among other things by restricting the possible mount points to
a directory that is controlled by root: /var/run/smb4k/<user> or
/run/smb4k/<user>. So, setting the mount prefix is not supported anymore. That
is why the entry was removed from the configuration dialog (like a few others
that also became obsolete).

In the release announcement I pointed out the change:
https://sourceforge.net/p/smb4k/blog/2025/12/smb4k-405-security-bug-fix-release/
 

Unfortunately, I haven't had the time to update the handbook, which I also
mentioned in the release announcement. This will be done with the release of
Smb4K 4.0.6. (By the way, the documentation you are refering to is for the Qt5
version of Smb4K. It is still correct in many areas, but outdated.)

-- 
You are receiving this mail because:
You are watching all bug changes.

Reply via email to