#VU120877 Permissions, Privileges, and Access Controls in smb4k - CVE-2025-66003
Published: January 2, 2026 / Updated: January 12, 2026
smb4k
KDE.org
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to application allows arbitrary mounts to be created within the Smb4KMountHelper::mount() function in smb4kmounthelper.cpp. A local user with ability to control content of a Samba network share can mount it over an existing local directory (e.g. /bin) and execute arbitrary code with root privileges.