Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-68764

Опубликовано: 05 янв. 2026
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

In the Linux kernel, the following vulnerability has been resolved: NFS: Automounted filesystems should inherit ro,noexec,nodev,sync flags When a filesystem is being automounted, it needs to preserve the user-set superblock mount options, such as the "ro" flag.

A security bypass vulnerability was found in the Linux kernel's NFS client implementation. When a filesystem is automounted, user-specified security-related mount flags such as "ro" (read-only), "noexec" (no execution), "nodev" (no device files), and "sync" are not properly inherited by the automounted filesystem. This allows operations that should be restricted by the parent mount options.

Отчет

This vulnerability allows bypassing mount security restrictions on NFS automounted filesystems. An attacker with access to an automounted NFS share could potentially execute binaries or write files when the parent mount was configured to prevent such actions. The impact depends on the specific mount flags used and what content is available on the NFS share.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10kernelFix deferred
Red Hat Enterprise Linux 6kernelOut of support scope
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelFix deferred
Red Hat Enterprise Linux 8kernel-rtFix deferred
Red Hat Enterprise Linux 9kernelFix deferred
Red Hat Enterprise Linux 9kernel-rtFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=2427121kernel: NFS: Automounted filesystems should inherit ro,noexec,nodev,sync flags

EPSS

Процентиль: 16%
0.00053
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

ubuntu
3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: NFS: Automounted filesystems should inherit ro,noexec,nodev,sync flags When a filesystem is being automounted, it needs to preserve the user-set superblock mount options, such as the "ro" flag.

nvd
3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: NFS: Automounted filesystems should inherit ro,noexec,nodev,sync flags When a filesystem is being automounted, it needs to preserve the user-set superblock mount options, such as the "ro" flag.

CVSS3: 5.5
msrc
3 месяца назад

NFS: Automounted filesystems should inherit ro,noexec,nodev,sync flags

debian
3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: N ...

github
3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: NFS: Automounted filesystems should inherit ro,noexec,nodev,sync flags When a filesystem is being automounted, it needs to preserve the user-set superblock mount options, such as the "ro" flag.

EPSS

Процентиль: 16%
0.00053
Низкий

6.1 Medium

CVSS3