| Name | CVE-2025-12801 |
| Description | A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| nfs-utils (PTS) | bullseye | 1:1.3.4-6+deb11u1 | vulnerable |
| bookworm | 1:2.6.2-4+deb12u1 | vulnerable | |
| trixie | 1:2.8.3-1 | vulnerable | |
| forky, sid | 1:2.8.7-1 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| nfs-utils | source | (unstable) | 1:2.8.6-1 |
[trixie] - nfs-utils <postponed> (Expose first fix via unstable; then handle within kernel-team maintenance)
[bookworm] - nfs-utils <postponed> (Expose first fix via unstable; then handle within kernel-team maintenance)
[bullseye] - nfs-utils <postponed> (Minor issue; can be fixed in next update; see notes for trixie/bookworm)
https://bugzilla.redhat.com/show_bug.cgi?id=2413081
https://lore.kernel.org/linux-nfs/20260305155948.11261-1-steved@redhat.com/
Requisite: https://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commit;h=7e8b36522f58657359c6842119fc516c6dd1baa4 (nfs-utils-2-8-6-rc5)
Requisite: https://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commit;h=42f01e6a78fed98f12437ac8b28cfb12b6bad056 (nfs-utils-2-8-6-rc5)
Requisite: https://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commit;h=51738ae56d922d4961e60dad73ad1c2d97d8d99b (nfs-utils-2-8-6-rc5)
Fixed by: https://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commit;h=f36bd900a899088ca1925de079bd58d6205a1f3c (nfs-utils-2-8-6-rc5)