<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:34:36 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:3938 — Moderate: nfs-utils security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:3938</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: libnfsidmap, AlmaLinux:8: libnfsidmap-devel, AlmaLinux:8: nfs-utils&lt;/p&gt;
&lt;p&gt;The nfs-utils packages provide a daemon for the kernel Network File System (NFS) server and related tools, which provides better performance than the traditional Linux NFS server used by most users. These packages also contain the mount.nfs, umount.nfs, and showmount programs.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* nfs-utils: rpc.mountd in the nfs-utils privilege escalation (CVE-2025-12801)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: libnfsidmap, AlmaLinux:8: libnfsidmap-devel, AlmaLinux:8: nfs-utils&lt;/p&gt;
&lt;p&gt;The nfs-utils packages provide a daemon for the kernel Network File System (NFS) server and related tools, which provides better performance than the traditional Linux NFS server used by most users. These packages also contain the mount.nfs, umount.nfs, and showmount programs.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* nfs-utils: rpc.mountd in the nfs-utils privilege escalation (CVE-2025-12801)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:3938</guid>
    </item>
    <item>
      <title>bdu:2026-09797</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-09797</link>
      <description>bdu:2026-09797</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-09797</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-12801</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-12801</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: nfs-utils, Alpaquita:25: nfs-utils, Alpaquita:stream: nfs-utils&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: nfs-utils, Alpaquita:25: nfs-utils, Alpaquita:stream: nfs-utils&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-12801</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0316 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0316</link>
      <description>certfr-2026-avi-0316</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0316</guid>
    </item>
    <item>
      <title>EUVD-2026-362225</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-362225</link>
      <description>EUVD-2026-362225</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-362225</guid>
    </item>
    <item>
      <title>fkie_cve-2025-12801</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-12801</link>
      <description>&lt;p&gt;A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the
privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any &amp;#39;root_squash&amp;#39; or &amp;#39;all_squash&amp;#39; attributes that would normally be expected to apply to that client.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the
privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any &amp;#39;root_squash&amp;#39; or &amp;#39;all_squash&amp;#39; attributes that would normally be expected to apply to that client.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-12801</guid>
    </item>
    <item>
      <title>GHSA-q8x7-j9x6-2fpc</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q8x7-j9x6-2fpc</link>
      <description>&lt;p&gt;A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the
privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any &amp;#39;root_squash&amp;#39; or &amp;#39;all_squash&amp;#39; attributes that would normally be expected to apply to that client.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the
privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any &amp;#39;root_squash&amp;#39; or &amp;#39;all_squash&amp;#39; attributes that would normally be expected to apply to that client.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q8x7-j9x6-2fpc</guid>
    </item>
    <item>
      <title>OESA-2026-2597 — nfs-utils security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2597</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: nfs-utils&lt;/p&gt;
&lt;p&gt;This is he nfs-utils tools package. It contains the showmount,mount.nfs,umount.nfs and libnfsidmap&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the
privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any &amp;amp;apos;root_squash&amp;amp;apos; or &amp;amp;apos;all_squash&amp;amp;apos; attributes that would normally be expected to apply to that client.(CVE-2025-12801)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: nfs-utils&lt;/p&gt;
&lt;p&gt;This is he nfs-utils tools package. It contains the showmount,mount.nfs,umount.nfs and libnfsidmap&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the
privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any &amp;amp;apos;root_squash&amp;amp;apos; or &amp;amp;apos;all_squash&amp;amp;apos; attributes that would normally be expected to apply to that client.(CVE-2025-12801)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2597</guid>
    </item>
    <item>
      <title>RHSA-2026:3938 — Red Hat Security Advisory: nfs-utils security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:3938</link>
      <description>&lt;p&gt;nfs-utils: rpc.mountd in the nfs-utils privilege escalation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nfs-utils: rpc.mountd in the nfs-utils privilege escalation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:3938</guid>
    </item>
    <item>
      <title>RHSA-2026:3941 — Red Hat Security Advisory: nfs-utils security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:3941</link>
      <description>&lt;p&gt;nfs-utils: rpc.mountd in the nfs-utils privilege escalation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nfs-utils: rpc.mountd in the nfs-utils privilege escalation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:3941</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-12801</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-12801</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 255 more&lt;/p&gt;
&lt;p&gt;A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any &amp;#39;root_squash&amp;#39; or &amp;#39;all_squash&amp;#39; attributes that would normally be expected to apply to that client.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 255 more&lt;/p&gt;
&lt;p&gt;A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any &amp;#39;root_squash&amp;#39; or &amp;#39;all_squash&amp;#39; attributes that would normally be expected to apply to that client.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-12801</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0615 — Red Hat Enterprise Linux (nfs-utils): Schwachstelle ermöglicht Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0615</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0615</guid>
    </item>
  </channel>
</rss>
