CVE-2025-12801

A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client.
Configurations

No configuration.

History

06 Mar 2026, 15:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:3939 -
  • () https://access.redhat.com/errata/RHSA-2026:3942 -

06 Mar 2026, 09:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:3941 -

06 Mar 2026, 04:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:3940 -

05 Mar 2026, 20:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:3938 -

04 Mar 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-04 16:16

Updated : 2026-03-06 15:16


NVD link : CVE-2025-12801

Mitre link : CVE-2025-12801

CVE.ORG link : CVE-2025-12801


JSON object : View

Products Affected

No product.

CWE
CWE-279

Incorrect Execution-Assigned Permissions