cifs.spnego key descriptions contain authority-bearing fields such as pid, uid, creduid, and upcall_target that cifs.upcall treats as kernel-originating inputs. However, userspace can also create keys of this type through request_key(2) or add_key(2), allowing those fields to be supplied without CIFS origin. Only accept cifs.spnego descriptions while CIFS is using its private spnego_cred to request the key.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:23259 https://access.redhat.com/errata/RHSA-2026:23259
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:23258 https://access.redhat.com/errata/RHSA-2026:23258
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:23329 https://access.redhat.com/errata/RHSA-2026:23329
This issue has been addressed in the following products: NVIDIA for RHEL 10 Via RHSA-2026:23395 https://access.redhat.com/errata/RHSA-2026:23395