Privilege Escalation in rpc.mountd Daemon for Linux NFS-Utils Package
CVE-2025-12801

6.5MEDIUM

What is CVE-2025-12801?

A vulnerability has been identified in the rpc.mountd daemon of the nfs-utils package for Linux, allowing a NFSv3 client to escalate privileges beyond those defined in the /etc/exports file at mount time. Specifically, this flaw permits the client to access any subdirectory or subtree of an exported directory, irrespective of the configured file permissions. Furthermore, it bypasses security attributes such as 'root_squash' and 'all_squash' that are typically meant to restrict access for that client. This could result in unauthorized file access and potential data breaches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Red Hat Enterprise Linux 10 1:2.8.3-0.el10_1.3

Red Hat Enterprise Linux 8 1:2.3.3-68.el8_10

Red Hat Enterprise Linux 9 1:2.5.4-38.el9_7.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.