Opened 7 months ago
Closed 7 months ago
#22922 closed enhancement (fixed)
nfs-utils-2.8.7
| Reported by: | Bruce Dubbs | Owned by: | Bruce Dubbs |
|---|---|---|---|
| Priority: | elevated | Milestone: | 13.1 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version.
Change History (8)
comment:1 by , 7 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 7 months ago
comment:3 by , 7 months ago
| Priority: | normal → elevated |
|---|
comment:6 by , 7 months ago
| Resolution: | fixed |
|---|---|
| Status: | closed → reopened |
| Summary: | nfs-utils-2.8.6 → nfs-utils-2.8.7 |
Now version 2.8.7,
comment:7 by , 7 months ago
I could not find release notes for this version, but a diff between versions 2.8.6 and 2.8.7 only showed one significant version:
--- nfs-utils-2.8.6/tools/nfsrahead/main.c 2026-03-07 12:18:39.000000000 -0600
+++ nfs-utils-2.8.7/tools/nfsrahead/main.c 2026-03-12 16:01:26.000000000 -0500
@@ -191,7 +191,7 @@
int main(int argc, char **argv)
{
int ret = 0, opt;
- struct device_info device;
+ struct device_info device = { 0 };
unsigned int readahead = 128, log_level, log_stderr = 0;
@@ -218,7 +218,11 @@
if ((argc - optind) != 1)
xlog_err("expected the device number of a BDI; is udev ok?");
- if ((ret = get_device_info(argv[optind], &device)) != 0 || device.fstype == NULL) {
+ ret = get_device_info(argv[optind], &device);
+ if (ret == -ENODEV) {
+ xlog(D_ALL, "skipping non-NFS device %s\n", argv[optind]);
+ goto out;
+ } else if (ret != 0 || device.fstype == NULL) {
xlog(D_GENERAL, "unable to find device %s\n", argv[optind]);
goto out;
}
comment:8 by , 7 months ago
| Resolution: | → fixed |
|---|---|
| Status: | reopened → closed |
Fixed at commits
9c33452c2c Update to shadow-4.19.4. ef0ab42935 Update to nfs-utils-2.8.7. 3b00d912ca Update to btrfs-progs-v6.19.
Note:
See TracTickets
for help on using tickets.

This release contains the following:
A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client.
Base Score: 6.5 MEDIUM