CVE-2026-46243: CIFSwitch, Another AI-Discovered Linux LPE

Last Updated: 2026-06-01T17:53:48Z

What’s Happening

CIFSwitch is a broadly-applicable Linux local privilege escalation vulnerability. There is a patch available for the mainline kernel, but distributions may or may not have patches available. It has been assigned CVE-2026-46243.

Vulnerable conditions (all must apply):

  • Circa 2007 or newer kernel.
  • cifs-utils version 6.14 and higher
  • Unprivileged users can create and mount namespaces
  • SELinux/AppArmor policies don’t impact vulnerability (different distros have different defaults)

See the provided Distro impact tables for details.

Actions

Test for vulnerability with the published PoC.

If you can apply the kernel patch directly, obviously do that. We’ll keep updating this for more patch info.

Notes

Debian has patched in Trixie-security.

3 Likes