{"id":"SUSE-SU-2026:1356-1","summary":"Security update for nfs-utils","details":"This update for nfs-utils fixes the following issue:\n\nSecurity fixes:\n\n- CVE-2025-12801: rpc.mountd allows a NFSv3 client to escalate their privileges and access subdirectories and subtrees\n  of an exported directory (bsc#1259204).\n\nOther fixes:\n\n- Split from nfs-utils into its own spec and changelog file (bsc#1246505).\n- Split legacy libnfsidmap0 into a separate spec file (bsc#1246505).\n","modified":"2026-04-16T08:30:20.378561Z","published":"2026-04-15T13:43:43Z","related":["CVE-2025-12801"],"upstream":["CVE-2025-12801"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20261356-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1246505"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259204"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-12801"}],"affected":[{"package":{"name":"libnfsidmap0","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP7","purl":"pkg:rpm/suse/libnfsidmap0&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.26-150600.28.19.1"}]}],"ecosystem_specific":{"binaries":[{"nfsidmap0-devel":"0.26-150600.28.19.1","libnfsidmap0":"0.26-150600.28.19.1","libnfsidmap1":"1.0-150600.28.19.1","nfs-client":"2.6.4-150600.28.19.1","nfs-doc":"2.6.4-150600.28.19.1","nfs-kernel-server":"2.6.4-150600.28.19.1","nfsidmap-devel":"1.0-150600.28.19.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1356-1.json"}},{"package":{"name":"nfs-utils","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP7","purl":"pkg:rpm/suse/nfs-utils&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.4-150600.28.19.1"}]}],"ecosystem_specific":{"binaries":[{"nfs-client":"2.6.4-150600.28.19.1","nfs-doc":"2.6.4-150600.28.19.1","nfs-kernel-server":"2.6.4-150600.28.19.1","nfsidmap-devel":"1.0-150600.28.19.1","nfsidmap0-devel":"0.26-150600.28.19.1","libnfsidmap0":"0.26-150600.28.19.1","libnfsidmap1":"1.0-150600.28.19.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1356-1.json"}},{"package":{"name":"libnfsidmap0","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/libnfsidmap0&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.26-150600.28.19.1"}]}],"ecosystem_specific":{"binaries":[{"libnfsidmap1":"1.0-150600.28.19.1","nfs-client":"2.6.4-150600.28.19.1","nfs-doc":"2.6.4-150600.28.19.1","nfs-kernel-server":"2.6.4-150600.28.19.1","nfsidmap-devel":"1.0-150600.28.19.1","nfsidmap0-devel":"0.26-150600.28.19.1","libnfsidmap0":"0.26-150600.28.19.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1356-1.json"}},{"package":{"name":"nfs-utils","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/nfs-utils&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.4-150600.28.19.1"}]}],"ecosystem_specific":{"binaries":[{"nfsidmap0-devel":"0.26-150600.28.19.1","libnfsidmap0":"0.26-150600.28.19.1","libnfsidmap1":"1.0-150600.28.19.1","nfs-client":"2.6.4-150600.28.19.1","nfs-doc":"2.6.4-150600.28.19.1","nfs-kernel-server":"2.6.4-150600.28.19.1","nfsidmap-devel":"1.0-150600.28.19.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1356-1.json"}},{"package":{"name":"libnfsidmap0","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/libnfsidmap0&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.26-150600.28.19.1"}]}],"ecosystem_specific":{"binaries":[{"libnfsidmap0":"0.26-150600.28.19.1","libnfsidmap1":"1.0-150600.28.19.1","nfs-client":"2.6.4-150600.28.19.1","nfs-doc":"2.6.4-150600.28.19.1","nfs-kernel-server":"2.6.4-150600.28.19.1","nfsidmap-devel":"1.0-150600.28.19.1","nfsidmap0-devel":"0.26-150600.28.19.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1356-1.json"}},{"package":{"name":"nfs-utils","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/nfs-utils&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.4-150600.28.19.1"}]}],"ecosystem_specific":{"binaries":[{"nfs-client":"2.6.4-150600.28.19.1","nfs-doc":"2.6.4-150600.28.19.1","nfs-kernel-server":"2.6.4-150600.28.19.1","nfsidmap-devel":"1.0-150600.28.19.1","nfsidmap0-devel":"0.26-150600.28.19.1","libnfsidmap0":"0.26-150600.28.19.1","libnfsidmap1":"1.0-150600.28.19.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1356-1.json"}},{"package":{"name":"libnfsidmap0","ecosystem":"openSUSE:Leap 15.6","purl":"pkg:rpm/opensuse/libnfsidmap0&distro=openSUSE%20Leap%2015.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.26-150600.28.19.1"}]}],"ecosystem_specific":{"binaries":[{"libnfsidmap0":"0.26-150600.28.19.1","libnfsidmap1":"1.0-150600.28.19.1","nfs-client":"2.6.4-150600.28.19.1","nfs-doc":"2.6.4-150600.28.19.1","nfs-kernel-server":"2.6.4-150600.28.19.1","nfsidmap-devel":"1.0-150600.28.19.1","nfsidmap0-devel":"0.26-150600.28.19.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1356-1.json"}},{"package":{"name":"nfs-utils","ecosystem":"openSUSE:Leap 15.6","purl":"pkg:rpm/opensuse/nfs-utils&distro=openSUSE%20Leap%2015.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.4-150600.28.19.1"}]}],"ecosystem_specific":{"binaries":[{"libnfsidmap0":"0.26-150600.28.19.1","libnfsidmap1":"1.0-150600.28.19.1","nfs-client":"2.6.4-150600.28.19.1","nfs-doc":"2.6.4-150600.28.19.1","nfs-kernel-server":"2.6.4-150600.28.19.1","nfsidmap-devel":"1.0-150600.28.19.1","nfsidmap0-devel":"0.26-150600.28.19.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1356-1.json"}}],"schema_version":"1.7.5"}