CVE-2025-12801
Last modified
CVE-2025-12801 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client.. EPSS estimates a 0.46% chance of exploitation in the next 30 days.
Description
A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Openshift Container Platform | 4.0 |
| Redhat | Enterprise Linux | 6.0 |
| Redhat | Enterprise Linux | 7.0 |
| Redhat | Enterprise Linux | 8.0 |
| Redhat | Enterprise Linux | 9.0 |
| Redhat | Enterprise Linux | 10.0 |
| Linux-Nfs | Nfs-Utils | All versions |
References
- https://access.redhat.com/errata/RHSA-2026:3938Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:3939Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:3940Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:3941Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:3942Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2025-12801Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2413081Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-12801?
How severe is CVE-2025-12801?
How do I fix CVE-2025-12801?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-1279The BM Content Builder plugin for WordPress is vulnerable to…8.8
- CVE-2025-12790A flaw was found in Rubygem MQTT. By default, the package us…7.4
- CVE-2025-12792The Mac App Store distribution of the Canva for Mac desktop …3.2
- CVE-2025-12793An uncontrolled DLL loading path vulnerability exists in Asu…7.8
- CVE-2025-12799A flaw was found in Jastow. Jastow is vulnerable to Cross-Si…6.5
- CVE-2025-12800The WP Shortcodes Plugin — Shortcodes Ultimate plugin for Wo…6.4
- CVE-2025-12803The Bold Page Builder plugin for WordPress is vulnerable to …6.4
- CVE-2025-12804The Booking Calendar plugin for WordPress is vulnerable to S…6.4
- CVE-2025-12805A flaw was found in Red Hat OpenShift AI (RHOAI) llama-stack…8.1
- CVE-2025-12807A security issue was discovered in DataMosaix Private Cloud,…8.7
- CVE-2025-12808Improper access control in Devolutions allows a View-only us…6.5
- CVE-2025-12809The Dokan Pro plugin for WordPress is vulnerable to unauthor…5.3
Are you affected by CVE-2025-12801?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
