OESA-2026-2688

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-2688
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-2688.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-2688
Upstream
Published
2026-06-24T13:09:30Z
Modified
2026-06-24T13:30:06.053420402Z
Summary
nfs-utils security update
Details

This is he nfs-utils tools package. It contains the showmount,mount.nfs,umount.nfs and libnfsidmap

Security Fix(es):

A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'rootsquash' or 'allsquash' attributes that would normally be expected to apply to that client.(CVE-2025-12801)

Database specific
{
    "severity": "Medium"
}
References

Affected packages

openEuler:20.03-LTS-SP4 / nfs-utils

Package

Name
nfs-utils
Purl
pkg:rpm/openEuler/nfs-utils&distro=openEuler-20.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.5.1-11.oe2003sp4

Ecosystem specific

{
    "aarch64": [
        "nfs-utils-2.5.1-11.oe2003sp4.aarch64.rpm",
        "nfs-utils-debuginfo-2.5.1-11.oe2003sp4.aarch64.rpm",
        "nfs-utils-debugsource-2.5.1-11.oe2003sp4.aarch64.rpm",
        "nfs-utils-devel-2.5.1-11.oe2003sp4.aarch64.rpm",
        "nfs-utils-help-2.5.1-11.oe2003sp4.aarch64.rpm"
    ],
    "src": [
        "nfs-utils-2.5.1-11.oe2003sp4.src.rpm"
    ],
    "x86_64": [
        "nfs-utils-2.5.1-11.oe2003sp4.x86_64.rpm",
        "nfs-utils-debuginfo-2.5.1-11.oe2003sp4.x86_64.rpm",
        "nfs-utils-debugsource-2.5.1-11.oe2003sp4.x86_64.rpm",
        "nfs-utils-devel-2.5.1-11.oe2003sp4.x86_64.rpm",
        "nfs-utils-help-2.5.1-11.oe2003sp4.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2688.json"