VDB
RHSA-2026%3A5127
RHSA-2026%3A5127
PUBLISHED
CVSS 6.5 MEDIUM
A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client.
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | rhcos-x86_64-418.94.202603181125-0 as a component of Red Hat OpenShift Container Platform 4.18 | *, 418.94.202603181125-0 |
| Red Hat | rhcos-s390x-418.94.202603181125-0 as a component of Red Hat OpenShift Container Platform 4.18 | 418.94.202603181125-0, * |
| Red Hat | rhcos-ppc64le-418.94.202603181125-0 as a component of Red Hat OpenShift Container Platform 4.18 | 418.94.202603181125-0, rhcos-ppc64le-418.94.202603181125-0 |
| Red Hat | rhcos-aarch64-418.94.202603181125-0 as a component of Red Hat OpenShift Container Platform 4.18 | rhcos-aarch64-418.94.202603181125-0, 418.94.202603181125-0 |
Timeline
- Mar 25, 2026 CVE Published
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 14, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2026:5127 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2413081 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2414683 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_5127.json advisory
- https://access.redhat.com/security/cve/CVE-2025-12801 advisory
- https://www.cve.org/CVERecord?id=CVE-2025-12801 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-12801 advisory
- https://access.redhat.com/security/cve/CVE-2025-61662 advisory
- https://www.cve.org/CVERecord?id=CVE-2025-61662 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-61662 advisory
- https://lists.gnu.org/archive/html/grub-devel/2025-11/msg00155.html advisory