The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade Rocky-Linux:9 pam_cifscreds-debuginfo to version 0:7.6-2.el9_8 or higher.
This issue was patched in RLSA-2026:39576.
Note: Versions mentioned in the description apply only to the upstream pam_cifscreds-debuginfo package and not the pam_cifscreds-debuginfo package as distributed by Rocky-Linux.
See How to fix? for Rocky-Linux:9 relevant fixed versions and status.
A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into entering a custom environment (namespace) containing a malicious NSS module. This forces the system to load the attacker's controlled NSS Module and configuration, allowing them to execute arbitrary commands as the root user, elevating their privileges and fully compromising the system.