Niedawno odkryta podatność w demonie rpc.mountd z pakietu nfs-utils dla Linuksa pozwala klientowi NFSv3 na escalation uprawnień przydzielonych mu w pliku /etc/exports w momencie montowania. W szczególności pozwala klientowi na dostęp do każdego podkatalogu lub poddrzewa eksportowanego katalogu, niezależnie od ustawionych uprawnień do plików oraz atrybutów 'root_squash' lub 'all_squash', które normalnie powinny mieć zastosowanie do tego klienta.
▸ Pokaż oryginał (EN)
A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NLinux Nfs Nfs Utils
APPLinux-Nfswszystkie wersjeRed Hat Enterprise Linux
OSRedhat10.06.07.08.09.0Red Hat OpenShift Container Platform
APPRedhat4.0
Powiązane podatności
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
RCE w Kibana Timelion — wykonanie kodu z uprawnieniami procesu
Jenkins Pipeline Groovy Plugin — bypass sandbox i wykonanie kodu (RCE)
Jenkins Script Security Plugin — sandbox bypass umożliwiający RCE