VDB
RHSA-2026%3A5873
RHSA-2026%3A5873
PUBLISHED
CVSS 6.5 MEDIUM
A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client.
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | rhcos-ppc64le-416.94.202603231244-0 as a component of Red Hat OpenShift Container Platform 4.16 | 416.94.202603231244-0 |
| Red Hat | rhcos-x86_64-416.94.202603231244-0 as a component of Red Hat OpenShift Container Platform 4.16 | 416.94.202603231244-0 |
| Red Hat | rhcos-s390x-416.94.202603231244-0 as a component of Red Hat OpenShift Container Platform 4.16 | 416.94.202603231244-0 |
| Red Hat | rhcos-aarch64-416.94.202603231244-0 as a component of Red Hat OpenShift Container Platform 4.16 | 416.94.202603231244-0 |
Timeline
- Apr 2, 2026 CVE Published
- May 13, 2026 CVE Updated
- May 15, 2026 Distribution Patch
- May 15, 2026 Distribution Patch
- May 15, 2026 Security Advisory
- May 15, 2026 Security Advisory
- May 15, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2026:5873 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2413081 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2430386 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_5873.json advisory
- https://access.redhat.com/security/cve/CVE-2025-12801 advisory
- https://www.cve.org/CVERecord?id=CVE-2025-12801 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-12801 advisory
- https://access.redhat.com/security/cve/CVE-2025-69419 advisory
- https://www.cve.org/CVERecord?id=CVE-2025-69419 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-69419 advisory