** Changed in: cifs-utils (Ubuntu)
       Status: New => Fix Released

** Changed in: cifs-utils (Ubuntu)
     Assignee: Alex Ramirez (kicchou) => (unassigned)

** Description changed:

- [ Impact ]
- 
-  * The patch for CVE-2026-12505 was reverted in LP: #2159053 because of a 
regression in kerberos mounts.
-  * Upstream cifs-utils has since fixed the regression, so we need to 
re-enable the CVE patch and SRU the regression fix.
- 
- [ Test Plan ]
- 
- TBD
- 
- [ Where problems could occur ]
- 
- TBD
- 
- [ Other Info ]
- 
- TBD
+ This bug was opened because of a regression in Kerberos mounts, but the
+ regression has since been fixed in Ubuntu.
  
  LP bug for CVE patch revert: 
https://bugs.launchpad.net/ubuntu/+source/cifs-utils/+bug/2159053
  CVE patch upstream: 
https://git.samba.org/?p=cifs-utils.git;a=commit;h=972c5b5ff95e3e812bc8daa72d0383654ab0dba7
- Regression fix upstream: 
https://git.samba.org/?p=cifs-utils.git;a=commit;h=70bb0f841aa8aafae8b1a1e7dc1cff5f6a26a27a
+ Regression fixes upstream: 
https://git.samba.org/?p=cifs-utils.git&a=search&h=70bb0f841aa8aafae8b1a1e7dc1cff5f6a26a27&st=commit&s=Fixes%3A+972c5b5ff95e+%28%22cifs.upcall%3A+remove+getpwuid%28%29+dependency%22%29

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2166482

Title:
  CVE-2026-12505: re-enable CVE patch + SRU kerberos regression fix

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/cifs-utils/+bug/2166482/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to