A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade nfs-utilsUpgrade libnfsidmapUpgrade nfsv4-client-utilsUpgrade libnfsidmap-develUpgrade nfs-utils-coreos | Mar 12, 2026 | Mar 5, 2026 |
| Oracle_linux | — | Upgrade nfsv4-client-utilsUpgrade libnfsidmapUpgrade libnfsidmap-develUpgrade nfs-utils-coreosUpgrade nfs-utils | Mar 10, 2026 | Mar 4, 2026 |
| Redhat Openshift | — | Upgrade rhcos | Aug 10, 2026 | Mar 4, 2026 |
| Redhat_linux | — | Upgrade nfsv4-client-utils-debuginfoUpgrade libnfsidmap-debuginfoUpgrade nfs-utils-coreosUpgrade libnfsidmap-develUpgrade nfsv4-client-utilsUpgrade libnfsidmapUpgrade nfs-utils-debugsourceUpgrade nfs-utilsUpgrade nfs-utils-debuginfoNo solution existsUpgrade nfs-utils-coreos-debuginfo | Mar 9, 2026 | Mar 4, 2026 |
| Rocky_linux | — | Upgrade nfs-utilsUpgrade libnfsidmap-develUpgrade nfs-utils-coreosUpgrade nfs-utils-coreos-debuginfoUpgrade libnfsidmapUpgrade nfs-utils-debugsourceUpgrade nfs-utils-debuginfoUpgrade nfsv4-client-utils-debuginfoUpgrade libnfsidmap-debuginfoUpgrade nfsv4-client-utils | Mar 11, 2026 | Mar 10, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub