A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:3939 https://access.redhat.com/errata/RHSA-2026:3939
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:3938 https://access.redhat.com/errata/RHSA-2026:3938
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:3940 https://access.redhat.com/errata/RHSA-2026:3940
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:3942 https://access.redhat.com/errata/RHSA-2026:3942
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:3941 https://access.redhat.com/errata/RHSA-2026:3941
Hi Can you please provide references to the upstream commit fixing this issue? Regards, Salvatore