CVE-2019-3689: nfs-utils: root-owned files stored in insecure /var/lib/nfs directory
Last updated 18 August 2025
Other sources
The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it can therefore trick processes running with root privileges into creating/overwriting files anywhere on the system.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-3689?
The severity of CVE-2019-3689 is critical, with a severity value of 9.8.
What is the affected software for CVE-2019-3689?
The affected software for CVE-2019-3689 is SUSE Linux Enterprise Server versions 12 and 15 with nfs-utils package versions 1.3.0-34.18.1 and 2.1.1-6.10.2 respectively.
What is the vulnerability description of CVE-2019-3689?
CVE-2019-3689 is a vulnerability in the nfs-utils package in SUSE Linux Enterprise Server 12 and 15 where the directory /var/lib/nfs is owned by statd:nogroup and contains files owned and managed by root, exposing potential security risks.
Is SUSE Linux Enterprise Server 12 vulnerable to CVE-2019-3689?
No, SUSE Linux Enterprise Server 12 is not vulnerable to CVE-2019-3689.
Is SUSE Linux Enterprise Server 15 vulnerable to CVE-2019-3689?
No, SUSE Linux Enterprise Server 15 is not vulnerable to CVE-2019-3689.