An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability allows local users ton perform arbitrary unmounts via smb4k mount helper
History

Thu, 08 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Jan 2026 14:45:00 +0000

Type Values Removed Values Added
Description An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability allows local users ton perform arbitrary unmounts via smb4k mount helper
Title Local users can perform arbitrary unmounts via smb4k mount helper due to lack of input validation
Weaknesses CWE-88
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: suse

Published: 2026-01-08T14:25:44.172Z

Updated: 2026-01-08T15:55:57.881Z

Reserved: 2025-11-19T08:52:54.076Z

Link: CVE-2025-66002

cve-icon Vulnrichment

Updated: 2026-01-08T15:55:51.396Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-08T15:15:43.590

Modified: 2026-01-08T18:08:18.457

Link: CVE-2025-66002

cve-icon Redhat

No data.