CVE-2025-12801
published 2026-03-04CVE-2025-12801: A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges…
PriorityP340medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.46%
37.1th percentile
A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the
privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nfs-utils | < nfs-utils 1:2.8.6-1 (forky) | nfs-utils 1:2.8.6-1 (forky) |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_oracle5.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-12801: A vulnerability was recently discovered in the rpc
osv·2026-03-04·CVSS 6.5
CVE-2025-12801 [MEDIUM] CVE-2025-12801: A vulnerability was recently discovered in the rpc
A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client.
GHSA
GHSA-q8x7-j9x6-2fpc: A vulnerability was recently discovered in the rpc
ghsa_unreviewed·2026-03-04
CVE-2025-12801 [MEDIUM] CWE-279 GHSA-q8x7-j9x6-2fpc: A vulnerability was recently discovered in the rpc
A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the
privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client.
Red Hat
nfs-utils: rpc.mountd in the nfs-utils privilege escalation
vendor_redhat·2026-03-04·CVSS 6.5
CVE-2025-12801 [MEDIUM] CWE-279 nfs-utils: rpc.mountd in the nfs-utils privilege escalation
nfs-utils: rpc.mountd in the nfs-utils privilege escalation
A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the
privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client.
A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the
privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirec
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (logback) — CVE-2024-12801
vendor_oracle·2025-07-15·CVSS 5.5
CVE-2024-12801 [LOW] Oracle Oracle Fusion Middleware Risk Matrix: Third Party (logback) — CVE-2024-12801
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (logback) vulnerability
CVE: CVE-2024-12801
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2025 (JUL 2025)
Debian
CVE-2025-12801: nfs-utils - A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-util...
vendor_debian·2025·CVSS 6.5
CVE-2025-12801 [MEDIUM] CVE-2025-12801: nfs-utils - A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-util...
A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1:2.8.6-1)
sid: resolved (fixed in 1:2.8.6-1)
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-12801 nfs-utils: rpc.mountd in the nfs-utils privilege escalation
bugzilla·2025-11-06·CVSS 6.5
CVE-2025-12801 [MEDIUM] CVE-2025-12801 nfs-utils: rpc.mountd in the nfs-utils privilege escalation
CVE-2025-12801 nfs-utils: rpc.mountd in the nfs-utils privilege escalation
A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the
privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:3939 https://access.redhat.com/errata/RHSA-2026:3939
---
This issue has been addressed in the following products:
Red Hat Enterprise Lin
Wiz
CVE-2026-4111 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-4111 [HIGH] CVE-2026-4111 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4111 :
Rocky Linux vulnerability analysis and mitigation
A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processed, the decompression routine may enter a state where internal logic prevents forward progress. This condition results in an infinite loop that continuously consumes CPU resources. Because the archive passes checksum validation and appears structurally valid, affected applications cannot detect the issue before processing. This can allow attackers to cause persistent denial-of-service conditions in services that automatically process archives.
Source : NVD
## 7.5
Score
Published March 13, 2026
Severity HIGH
CNA Score
Wiz
CVE-2025-14905 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-14905 [MEDIUM] CVE-2025-14905 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14905 :
Rocky Linux vulnerability analysis and mitigation
schema_attr_enum_callback
schema.c
Source : NVD
## 7.2
Score
Published February 23, 2026
Severity HIGH
CNA Score 7.2
Affected Technologies
Rocky Linux
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 64.4
Exploitation Probability (EPSS) 0.5
Affected packages and libraries
python3-lib389
389-ds-base-legacy-tools
Sources
NVD
AlmaLinux 8 Severity MEDIUM Has Fix Added at: Mar 29, 2026
AlmaLinux 9 Severity MEDIUM Has Fix Added at: Mar 02, 2026
Debian 11, 12, 13 Severity HIGH No Fix Added at: Feb 24, 2026
Echo Severity HIGH No Fix Added at: Feb 24, 2026
Red Hat 6, 7 Severity MEDIUM No Fix Added at: F
Wiz
CVE-2026-1299 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.0
CVE-2026-1299 [MEDIUM] CVE-2026-1299 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1299 :
Rocky Linux vulnerability analysis and mitigation
The
email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email headers when
serializing an email message allowing for header injection when an email
is serialized. This is only applicable if using "LiteralHeader" writing headers that don't respect email folding rules, the new behavior will reject the incorrectly folded headers in "BytesGenerator".
Source : NVD
## 6
Score
Published January 23, 2026
Severity MEDIUM
CNA Score 6.0
Affected Technologies
Rocky Linux
Python Interpreter
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 13.5
Exploitation Probability (EPSS) N/A
Affected pac
Wiz
CVE-2025-12801 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-12801 [MEDIUM] CVE-2025-12801 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-12801 :
Rocky Linux vulnerability analysis and mitigation
A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the
privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client.
Source : NVD
## 6.5
Score
Published March 4, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
Rocky Linux
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probabilit
Wiz
CVE-2026-4647 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-4647 [MEDIUM] CVE-2026-4647 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4647 :
OpenShift Node vulnerability analysis and mitigation
A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks.
Source : NVD
## 6.1
Score
Published March 23, 2026
Severity MEDIUM
CNA Score 6.1
Affected Technologies
OpenShift Node
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV
Wiz
CVE-2025-15366 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.9
CVE-2025-15366 [MEDIUM] CVE-2025-15366 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-15366 :
Rocky Linux vulnerability analysis and mitigation
The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.
Source : NVD
## 5.9
Score
Published January 20, 2026
Severity MEDIUM
CNA Score 5.9
Affected Technologies
Rocky Linux
Python Interpreter
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 23.8
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
python311-testsuite
python36:3.6::python-pymongo
Sources
AlmaLinux 8 Severity MEDIUM Has Fix Added at: Feb 08, 2026
AlmaLinux 9 Severity MEDIUM Has Fix Added at: Mar 12, 2026
Chainguard
Wiz
CVE-2026-3441 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-3441 [MEDIUM] CVE-2026-3441 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3441 :
OpenShift Node vulnerability analysis and mitigation
A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service.
Source : NVD
## 7.1
Score
Published March 16, 2026
Severity HIGH
CNA Score 6.1
Affected Technologies
OpenShift Node
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.3
Exploitation Probability (EPSS) N/A
Affected pac
Wiz
CVE-2026-1761 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.6
CVE-2026-1761 [HIGH] CVE-2026-1761 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1761 :
Rocky Linux vulnerability analysis and mitigation
A flaw was found in libsoup. This stack-based buffer overflow vulnerability occurs during the parsing of multipart HTTP responses due to an incorrect length calculation. A remote attacker can exploit this by sending a specially crafted multipart HTTP response, which can lead to memory corruption. This issue may result in application crashes or arbitrary code execution in applications that process untrusted server responses, and it does not require authentication or user interaction.
Source : NVD
## 8.6
Score
Published February 2, 2026
Severity HIGH
CNA Score 8.6
Affected Technologies
Rocky Linux
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Explo
Wiz
CVE-2026-0719 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.6
CVE-2026-0719 [HIGH] CVE-2026-0719 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0719 :
Rocky Linux vulnerability analysis and mitigation
A flaw was identified in the NTLM authentication handling of the libsoup HTTP library, used by GNOME and other applications for network communication. When processing extremely long passwords, an internal size calculation can overflow due to improper use of signed integers. This results in incorrect memory allocation on the stack, followed by unsafe memory copying. As a result, applications using libsoup may crash unexpectedly, creating a denial-of-service risk.
Source : NVD
## 8.6
Score
Published January 8, 2026
Severity HIGH
CNA Score 8.6
Affected Technologies
Rocky Linux
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Pe
Wiz
CVE-2026-3442 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-3442 [MEDIUM] CVE-2026-3442 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3442 :
OpenShift Node vulnerability analysis and mitigation
A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.
Source : NVD
## 7.1
Score
Published March 16, 2026
Severity HIGH
CNA Score 6.1
Affected Technologies
OpenShift Node
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.3
Exploit
Wiz
CVE-2026-0865 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.9
CVE-2026-0865 [MEDIUM] CVE-2026-0865 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0865 :
Rocky Linux vulnerability analysis and mitigation
User-controlled header names and values containing newlines can allow injecting HTTP headers.
Source : NVD
## 5.9
Score
Published January 20, 2026
Severity MEDIUM
CNA Score 5.9
Affected Technologies
Rocky Linux
Python Interpreter
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 32.7
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
python3.15-freethreading-libs
python313-nogil
Sources
NVD
AlmaLinux 8 Severity MEDIUM Has Fix Added at: Feb 08, 2026
AlmaLinux 9 Severity MEDIUM Has Fix Added at: Mar 13, 2026
CBL-Mariner 2.0 Severity MEDIUM Has Fix Added at: Mar 10, 2026
CBL-Mariner 3.0 Severity
Wiz
CVE-2025-15367 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.9
CVE-2025-15367 [MEDIUM] CVE-2025-15367 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-15367 :
Rocky Linux vulnerability analysis and mitigation
The poplib module, when passed a user-controlled command, can have
additional commands injected using newlines. Mitigation rejects commands
containing control characters.
Source : NVD
## 5.9
Score
Published January 20, 2026
Severity MEDIUM
CNA Score 5.9
Affected Technologies
Rocky Linux
Python Interpreter
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 23.8
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
python310-tk
python312-tk
Sources
AlmaLinux 8 Severity MEDIUM Has Fix Added at: Feb 08, 2026
AlmaLinux 9 Severity MEDIUM Has Fix Added at: Mar 12, 2026
Chainguard Has Fix Added at: Jan 28
Wiz
CVE-2025-14523 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.2
CVE-2025-14523 [HIGH] CVE-2025-14523 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14523 :
Rocky Linux vulnerability analysis and mitigation
A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.
Source : NVD
## 8.2
Score
Published December 11, 2025
Severity HIGH
CNA Score 8.2
Affected Technologies
Rocky Linux
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
https://access.redhat.com/errata/RHSA-2026:3938https://access.redhat.com/errata/RHSA-2026:3939https://access.redhat.com/errata/RHSA-2026:3940https://access.redhat.com/errata/RHSA-2026:3941https://access.redhat.com/errata/RHSA-2026:3942https://access.redhat.com/errata/RHSA-2026:5127https://access.redhat.com/errata/RHSA-2026:5606https://access.redhat.com/errata/RHSA-2026:5867https://access.redhat.com/errata/RHSA-2026:5873https://access.redhat.com/errata/RHSA-2026:5877https://access.redhat.com/security/cve/CVE-2025-12801https://bugzilla.redhat.com/show_bug.cgi?id=2413081
2026-03-04
Published