VDB

RHSA-2026%3A5873

RHSA-2026%3A5873 PUBLISHED CVSS 6.5 MEDIUM

A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client.

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
Red Hatrhcos-ppc64le-416.94.202603231244-0 as a component of Red Hat OpenShift Container Platform 4.16416.94.202603231244-0
Red Hatrhcos-x86_64-416.94.202603231244-0 as a component of Red Hat OpenShift Container Platform 4.16416.94.202603231244-0
Red Hatrhcos-s390x-416.94.202603231244-0 as a component of Red Hat OpenShift Container Platform 4.16416.94.202603231244-0
Red Hatrhcos-aarch64-416.94.202603231244-0 as a component of Red Hat OpenShift Container Platform 4.16416.94.202603231244-0

Timeline

  • Apr 2, 2026 CVE Published
  • May 13, 2026 CVE Updated
  • May 15, 2026 Distribution Patch
  • May 15, 2026 Distribution Patch
  • May 15, 2026 Security Advisory
  • May 15, 2026 Security Advisory
  • May 15, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›