CVE-2020-14342: Fedoraproject Fedora

High severity, CVSS 7.0. EPSS: 0.7% chance of exploitation in the next 30 days.

It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject arbitrary commands. An attacker able to invoke mount.cifs with special permission, such as via sudo rules, could use this flaw to escalate their privileges.

Affected products

  • Fedoraproject Fedora: version 32 only; version 33 only
  • Opensuse Leap: version 15.1 only
  • Samba Cifs-Utils: from 5.6, up to and including 6.10

Published 2020-09-09. Last modified 2026-06-17.