CVE-2025-12801
A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.46%
- CWE
- CWE-279
- Published
- 2026-03-04
- Last modified
- 2026-09-01
Affected products
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Enterprise Linux 9.4 Extended Update Support
- Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support
- Red Hat Red Hat Ceph Storage 8
- Red Hat Red Hat OpenShift Container Platform 4.18
- Red Hat Red Hat OpenShift Container Platform 4.17
Weakness type
Related vulnerabilities
- CVE-2026-46388 — osquery: Unprivileged users can temporarily read file carve contents
- CVE-2026-4948 — Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization
- CVE-2026-20062 — A vulnerability in the CLI of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software in...
- CVE-2025-14025 — Ansible-automation-platform/aap-gateway: aap-gateway: read-only personal access token (pat) bypasses write restrictions
- CVE-2025-36228 — Incorrect Execution-Assigned Permissions in IBM Aspera Faspex
- CVE-2025-13663 — Quartus Prime Pro Edition Installer Advisory
- CVE-2024-25621 — containerd affected by a local privilege escalation via wide permissions on CRI directory
- CVE-2025-30001 — Apache StreamPark: Authenticated users can trigger remote command execution