Opened 7 months ago

Closed 7 months ago

#22922 closed enhancement (fixed)

nfs-utils-2.8.7

Reported by: Bruce Dubbs Owned by: Bruce Dubbs
Priority: elevated Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (8)

comment:1 by Bruce Dubbs, 7 months ago

Owner: changed from blfs-book to Bruce Dubbs
Status: new → assigned

comment:2 by Bruce Dubbs, 7 months ago

This release contains the following:

  • CVE-2025-12801 resolved
  • gssd improvements.
  • nfsrahead updates.
  • nfsdctl fixes.
  • A number of other bug fixes.

A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client.

Base Score: 6.5 MEDIUM

comment:3 by Douglas R. Reno, 7 months ago

Priority: normal → elevated

comment:4 by Bruce Dubbs, 7 months ago

Fixed at commit c19b811ed6.

Leaving open for security advisory.

comment:5 by Douglas R. Reno, 7 months ago

Resolution: → fixed
Status: assigned → closed

SA-13.0-007 issued

comment:6 by Bruce Dubbs, 7 months ago

Resolution: fixed
Status: closed → reopened
Summary: nfs-utils-2.8.6 → nfs-utils-2.8.7

Now version 2.8.7,

comment:7 by Bruce Dubbs, 7 months ago

I could not find release notes for this version, but a diff between versions 2.8.6 and 2.8.7 only showed one significant version:

--- nfs-utils-2.8.6/tools/nfsrahead/main.c      2026-03-07 12:18:39.000000000 -0600
+++ nfs-utils-2.8.7/tools/nfsrahead/main.c      2026-03-12 16:01:26.000000000 -0500
@@ -191,7 +191,7 @@
 int main(int argc, char **argv)
 {
        int ret = 0, opt;
-       struct device_info device;
+       struct device_info device = { 0 };
        unsigned int readahead = 128, log_level, log_stderr = 0;
 
 
@@ -218,7 +218,11 @@
        if ((argc - optind) != 1)
                xlog_err("expected the device number of a BDI; is udev ok?");
 
-       if ((ret = get_device_info(argv[optind], &device)) != 0 || device.fstype == NULL) {
+       ret = get_device_info(argv[optind], &device);
+       if (ret == -ENODEV) {
+               xlog(D_ALL, "skipping non-NFS device %s\n", argv[optind]);
+               goto out;
+       } else if (ret != 0 || device.fstype == NULL) {
                xlog(D_GENERAL, "unable to find device %s\n", argv[optind]);
                goto out;
        }

comment:8 by Bruce Dubbs, 7 months ago

Resolution: → fixed
Status: reopened → closed

Fixed at commits

9c33452c2c Update to shadow-4.19.4.
ef0ab42935 Update to nfs-utils-2.8.7.
3b00d912ca Update to btrfs-progs-v6.19.
Note: See TracTickets for help on using tickets.