SUSE openSUSE Tumbleweed smb4k Argument Injection Vulnerability Allowing Arbitrary Unmounts

Vulnerability

A vulnerability in the smb4k mount helper component of openSUSE Tumbleweed has been identified, allowing local users to perform arbitrary unmounts. This issue arises from improper input validation, enabling exploitation through the KAuth D-Bus interface. The vulnerability could lead to a local root exploit if the attacker can control the contents of a mounted Samba share.

Impact

Exploitation of this vulnerability allows local users to unmount arbitrary file systems, potentially causing a system outage. In certain contexts, it could lead to information leaks or privilege escalation.

Reproduction

The vulnerability can be reproduced by invoking the smb4k mount helper's unmount function via D-Bus, with a path that does not match any existing Samba mounts. This bypasses the helper's verification logic, allowing the unmounting of arbitrary file systems.

Remediation

Users can update to smb4k version 4.0.5, which addresses the vulnerability by implementing proper input validation and restricting unmount actions to predefined directories.

Added: Jan 8, 2026, 3:25 PM
Updated: Jan 8, 2026, 6:43 PM

Vulnerability Rating

Custom Algorithm
spread
2.4
impact
3.1
exploitability
4.3
remediation
7.7
relevance
1.9
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.