Logo
vulnerabilityCVE-2025-12801
Name
CVE-2025-12801
Source
NVD ( link)Debian ( link)
Description
A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
nfs-utils
Patched

Vulnerability Ratings#


6.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.8.6
Not Affected
buildroot
master
2.9.1
Not Affected
openwrt
master
2.9.1-r1
Not Affected
yocto
kirkstone
2.6.1
Not Affected
yocto
master
2.9.2
Not Affected

Resolved with patches#


nfs-utils (yocto:scarthgap)

#
Title
Author
Resolve
1
Fix access checks when mounting subdirectories in NFSv3
Trond Myklebust <trond.myklebust@hammerspace.com>
CVE-2025-12801
2
support: Add a mini-library to extract and apply RPC
Trond Myklebust <trond.myklebust@hammerspace.com>
CVE-2025-12801
3
reexport.c: Some Distros need the following include to
Steve Dickson <steved@redhat.com>
CVE-2025-12801
4
mountd: Minor refactor of get_rootfh()
Trond Myklebust <trond.myklebust@hammerspace.com>
CVE-2025-12801
5
mountd: Separate lookup of the exported directory and the
Trond Myklebust <trond.myklebust@hammerspace.com>
CVE-2025-12801
6
NFS export symlink vulnerability fix
Christopher Bii <christopherbii@hyub.org>
CVE-2025-12801