Public bug reported:

[ Impact ]

 * The patch for CVE-2026-12505 was reverted in LP #2159053 because of a 
regression in kerberos mounts.
 * Upstream cifs-utils has since fixed the regression, so we need to re-enable 
the CVE patch and SRU the regression fix.

[ Test Plan ]

TBD

[ Where problems could occur ]

TBD

[ Other Info ]

TBD

LP bug for CVE patch revert: 
https://bugs.launchpad.net/ubuntu/+source/cifs-utils/+bug/2159053
CVE patch upstream: 
https://git.samba.org/?p=cifs-utils.git;a=commit;h=972c5b5ff95e3e812bc8daa72d0383654ab0dba7
Regression fix upstream: 
https://git.samba.org/?p=cifs-utils.git;a=commit;h=70bb0f841aa8aafae8b1a1e7dc1cff5f6a26a27a

** Affects: cifs-utils (Ubuntu)
     Importance: Undecided
     Assignee: Alex Ramirez (kicchou)
         Status: New

** Summary changed:

- fix for fix for CVE-2026-12505 introduced regression with kerberos mounts
+ CVE-2026-12505: re-enable CVE patch + SRU kerberos regression fix

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2166482

Title:
  CVE-2026-12505: re-enable CVE patch + SRU kerberos regression fix

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/cifs-utils/+bug/2166482/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to