Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-3940

Опубликовано: 05 мар. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-3940: nfs-utils security update (MODERATE)

[2.5.4-38.0.1.el9_7.3]

  • spec: remove multiple warnings when upgrading nfs-utils with gssproxy [Orabug: 36044562]

[2.5.4-38.3]

  • Add requires for selinux-policy (RHEL-127104)

[2.5.4-38.2]

  • Replace statfs64 with statfs (RHEL-127104)
  • NFS export symlink vulnerability fix (RHEL-127104)
  • mountd: Minor refactor of get_rootfh() (RHEL-127104)
  • mountd: Separate lookup of the exported directory and the mount path (RHEL-127104)
  • support: Add a mini-library to extract and apply RPC credentials (RHEL-127104)
  • Fix access checks when mounting subdirectories in NFSv3 (RHEL-127104) Resolves: CVE-2025-12801

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

libnfsidmap

2.5.4-38.0.1.el9_7.3

libnfsidmap-devel

2.5.4-38.0.1.el9_7.3

nfs-utils

2.5.4-38.0.1.el9_7.3

nfs-utils-coreos

2.5.4-38.0.1.el9_7.3

nfsv4-client-utils

2.5.4-38.0.1.el9_7.3

Oracle Linux x86_64

libnfsidmap

2.5.4-38.0.1.el9_7.3

libnfsidmap-devel

2.5.4-38.0.1.el9_7.3

nfs-utils

2.5.4-38.0.1.el9_7.3

nfs-utils-coreos

2.5.4-38.0.1.el9_7.3

nfsv4-client-utils

2.5.4-38.0.1.el9_7.3

Связанные CVE

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 месяца назад

A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client.

CVSS3: 6.5
redhat
около 1 месяца назад

A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client.

CVSS3: 6.5
nvd
около 1 месяца назад

A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client.

CVSS3: 6.5
debian
около 1 месяца назад

A vulnerability was recently discovered in the rpc.mountd daemon in th ...

rocky
28 дней назад

Moderate: nfs-utils security update