Local users can perform arbitrary unmounts via smb4k mount helper due to lack of input validation
Vulnerability Description
An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability allows local users ton perform arbitrary unmounts via smb4k mount helper
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-66002
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Matthias Gerstner of SUSE
References
More from https://github.com/KDE/
View All →Affected Vendor
https://github.com/KDE/
View all reports →