Vulnerabilities
CIFSwitch Hands Out Root on Multiple Linux Distros via a Forged CIFS Auth Key
A new Linux kernel LPE called CIFSwitch lets unprivileged local users forge a cifs.spnego key description and hijack the kernel key-request mechanism, getting cifs.upcall to run attacker-controlled NSS code as root. PoC is public; CVE assignment is pending.