Smb4k Local Root Exploit Vulnerability via Privileged Mount Helper

Vulnerability

A vulnerability in Smb4k's mount helper allows local users to execute a local root exploit by manipulating the contents of a Samba share. This issue arises from the mount helper's lack of input validation and oversight, enabling unauthorized unmounting of file systems and potential exploitation of system programs. The vulnerability affects Smb4k versions prior to 4.0.5.

Impact

Exploitation of this vulnerability could lead to unauthorized access to root privileges on the affected system.

Reproduction

The vulnerability can be reproduced by accessing a Samba share with write permissions and using the Smb4k mount helper to mount the share. The mount helper will not properly validate the mount point, allowing for the execution of a local root exploit by placing crafted binaries on the share that could be executed by privileged processes.

Remediation

Users can update to Smb4k version 4.0.5, which addresses the vulnerability by implementing proper input validation and restricting the mount helper's actions to safe, predefined directories.

Added: Jan 8, 2026, 3:24 PM
Updated: Jan 8, 2026, 6:43 PM

Vulnerability Rating

Custom Algorithm
spread
2.4
impact
2.5
exploitability
4.3
remediation
7.7
relevance
1.8
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.