Privilege Escalation in rpc.mountd Daemon for Linux NFS-Utils Package
CVE-2025-12801
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 4 March 2026
What is CVE-2025-12801?
A vulnerability has been identified in the rpc.mountd daemon of the nfs-utils package for Linux, allowing a NFSv3 client to escalate privileges beyond those defined in the /etc/exports file at mount time. Specifically, this flaw permits the client to access any subdirectory or subtree of an exported directory, irrespective of the configured file permissions. Furthermore, it bypasses security attributes such as 'root_squash' and 'all_squash' that are typically meant to restrict access for that client. This could result in unauthorized file access and potential data breaches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Red Hat Enterprise Linux 10 1:2.8.3-0.el10_1.3
Red Hat Enterprise Linux 8 1:2.3.3-68.el8_10
Red Hat Enterprise Linux 9 1:2.5.4-38.el9_7.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved