← Back

CVE-2025-12801

nvd nist
Published: Mar 4, 2026Modified: Jun 30, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: secalert@redhat.com (Secondary)

Description

A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client.

Affected (7)

2 products
Enterprise Linux
Openshift Container Platform
1 product
Nfs Utils
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 10.0
Version 6.0
Version 7.0
Version 8.0
Version 9.0
Version 4.0
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

References (12)

Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Issue TrackingThird Party Advisory

Timeline

No history available yet.