CVE-2025-12801

EUVD-2025-208274
A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the
privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 5%
Affected Products (NVD)
VendorProductVersion
redhatopenshift_container_platform
4.0
redhatenterprise_linux
6.0
redhatenterprise_linux
7.0
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0
redhatenterprise_linux
10.0
linux-nfsnfs-utils
-
𝑥
= Vulnerable software versions
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libnfsidmap0
suse enterprise desktop 15 SP7
0.26-150600.28.19.1
fixed
suse enterprise sap 15 SP7
0.26-150600.28.19.1
fixed
suse enterprise server 15 SP6
0.26-150600.28.19.1
fixed
suse enterprise server 15 SP7
0.26-150600.28.19.1
fixed
libnfsidmap1
suse enterprise desktop 15 SP7
1.0-150600.28.19.1
fixed
suse enterprise sap 15 SP7
1.0-150600.28.19.1
fixed
suse enterprise server 15 SP6
1.0-150600.28.19.1
fixed
suse enterprise server 15 SP7
1.0-150600.28.19.1
fixed
nfs-client
suse enterprise desktop 15 SP7
2.6.4-150600.28.19.1
fixed
suse enterprise sap 15 SP7
2.6.4-150600.28.19.1
fixed
suse enterprise server 15 SP6
2.6.4-150600.28.19.1
fixed
suse enterprise server 15 SP7
2.6.4-150600.28.19.1
fixed
nfs-doc
suse enterprise desktop 15 SP7
2.6.4-150600.28.19.1
fixed
suse enterprise sap 15 SP7
2.6.4-150600.28.19.1
fixed
suse enterprise server 15 SP6
2.6.4-150600.28.19.1
fixed
suse enterprise server 15 SP7
2.6.4-150600.28.19.1
fixed
nfs-kernel-server
suse enterprise desktop 15 SP7
2.6.4-150600.28.19.1
fixed
suse enterprise sap 15 SP7
2.6.4-150600.28.19.1
fixed
suse enterprise server 15 SP6
2.6.4-150600.28.19.1
fixed
suse enterprise server 15 SP7
2.6.4-150600.28.19.1
fixed
nfsidmap-devel
suse enterprise desktop 15 SP7
1.0-150600.28.19.1
fixed
suse enterprise sap 15 SP7
1.0-150600.28.19.1
fixed
suse enterprise server 15 SP6
1.0-150600.28.19.1
fixed
suse enterprise server 15 SP7
1.0-150600.28.19.1
fixed
nfsidmap0-devel
suse enterprise desktop 15 SP7
0.26-150600.28.19.1
fixed
suse enterprise sap 15 SP7
0.26-150600.28.19.1
fixed
suse enterprise server 15 SP6
0.26-150600.28.19.1
fixed
suse enterprise server 15 SP7
0.26-150600.28.19.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
libnfsidmap
RHEL 8
1:2.3.3-68.el8_10
fixed
RHEL 9
1:2.5.4-38.el9_7.3
fixed
libnfsidmap-devel
RHEL 8
1:2.3.3-68.el8_10
fixed
RHEL 9
1:2.5.4-38.el9_7.3
fixed
nfs-utils
RHEL 8
1:2.3.3-68.el8_10
fixed
RHEL 9
1:2.5.4-38.el9_7.3
fixed
nfs-utils-coreos
RHEL 9
1:2.5.4-38.el9_7.3
fixed
nfsv4-client-utils
RHEL 9
1:2.5.4-38.el9_7.3
fixed