CVE-2025-12801CWE-279CWE-732

CVE-2025-12801

Medium · published March 4, 2026

CVSS v3.1
6.5
EPSS
0%
Percentile
38.4
In the wild
Unconfirmed
What it is

A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the

privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client.

The record
Technical detail
CVSS v3.1
6.5 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00462 · 38.4th percentile
Weaknesses
CWE-279 · Incorrect Execution-Assigned Permissions; CWE-732 · Incorrect Permission Assignment for Critical Resource
Published
2026-03-04T21:16Z
Affected products (7)
ProductVersionsFixed in
redhat/openshift_container_platformall versions
redhat/enterprise_linuxall versions
redhat/enterprise_linuxall versions
redhat/enterprise_linuxall versions
redhat/enterprise_linuxall versions
redhat/enterprise_linuxall versions
linux-nfs/nfs-utilsall versions
References (12)
EPSS history
Timeline
  • 04 MAR 15:25Z
    Nfs-utils: rpc.mountd in the nfs-utils privilege escalation
    cvelistv5