CVE-2025-12801

NameCVE-2025-12801
DescriptionA vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
nfs-utils (PTS)bullseye1:1.3.4-6+deb11u1vulnerable
bookworm1:2.6.2-4+deb12u1vulnerable
trixie1:2.8.3-1vulnerable
forky, sid1:2.8.7-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
nfs-utilssource(unstable)1:2.8.6-1

Notes

[trixie] - nfs-utils <postponed> (Expose first fix via unstable; then handle within kernel-team maintenance)
[bookworm] - nfs-utils <postponed> (Expose first fix via unstable; then handle within kernel-team maintenance)
[bullseye] - nfs-utils <postponed> (Minor issue; can be fixed in next update; see notes for trixie/bookworm)
https://bugzilla.redhat.com/show_bug.cgi?id=2413081
https://lore.kernel.org/linux-nfs/20260305155948.11261-1-steved@redhat.com/
Requisite: https://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commit;h=7e8b36522f58657359c6842119fc516c6dd1baa4 (nfs-utils-2-8-6-rc5)
Requisite: https://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commit;h=42f01e6a78fed98f12437ac8b28cfb12b6bad056 (nfs-utils-2-8-6-rc5)
Requisite: https://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commit;h=51738ae56d922d4961e60dad73ad1c2d97d8d99b (nfs-utils-2-8-6-rc5)
Fixed by: https://git.linux-nfs.org/?p=steved/nfs-utils.git;a=commit;h=f36bd900a899088ca1925de079bd58d6205a1f3c (nfs-utils-2-8-6-rc5)

Search for package or bug name: Reporting problems