๐Ÿ” CVE Alert

CVE-2026-89671

CRITICAL 9.1

nfsd: gate nfs3 setacl by argp->mask

CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: nfsd: gate nfs3 setacl by argp->mask nfsd3_proc_setacl() calls set_posix_acl() unconditionally for both ACL_TYPE_ACCESS and ACL_TYPE_DEFAULT, passing argp->acl_access and argp->acl_default verbatim. The NFSv3 ACL decoder only populates those pointers when the corresponding mask bit is set: nfs3svc_decode_setaclargs() if (args->mask & NFS_ACL) decode into acl_access if (args->mask & NFS_DFACL) decode into acl_default /* otherwise the pointer stays NULL (pc_argzero) */ nfsd3_proc_setacl() set_posix_acl(.., ACL_TYPE_ACCESS, argp->acl_access) set_posix_acl(.., ACL_TYPE_DEFAULT, argp->acl_default) set_posix_acl(idmap, dentry, type, NULL) is the VFS "remove this ACL type" operation. A NULL pointer that means "the client did not send this arm" is therefore indistinguishable from "the client asked to remove this ACL". A SETACL with mask=NFS_ACL silently drops the directory's default ACL; mask=0 drops both. The sibling nfsd3_proc_getacl() already consults argp->mask before touching each arm; mirror that in setacl. Fix by wrapping each set_posix_acl() call in the matching mask bit check and initializing error to 0 before inode_lock so that a request with neither bit set leaves the on-disk ACLs untouched and returns nfs_ok. The out_drop_lock path and the unconditional posix_acl_release() at out: are preserved; both NULL-tolerate the skipped arms.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new critical vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
a257cdd0e2179630d3201c32ba14d7fcb3c3a055 < 3be1d8611dae4829e4608007db29f4a8748c37b2 a257cdd0e2179630d3201c32ba14d7fcb3c3a055 < 68a80b26efdff1d09f8ae1773c6a915abb9e191d a257cdd0e2179630d3201c32ba14d7fcb3c3a055 < b3bff820d068ea59767d4e91a3258231a879da5f a257cdd0e2179630d3201c32ba14d7fcb3c3a055 < ff99ed007f065198fd723152405c22aa558f700b a257cdd0e2179630d3201c32ba14d7fcb3c3a055 < 453d7198a0ab07a12d46e0575861ac7b932da17e
Linux / Linux
2.6.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/3be1d8611dae4829e4608007db29f4a8748c37b2 git.kernel.org: https://git.kernel.org/stable/c/68a80b26efdff1d09f8ae1773c6a915abb9e191d git.kernel.org: https://git.kernel.org/stable/c/b3bff820d068ea59767d4e91a3258231a879da5f git.kernel.org: https://git.kernel.org/stable/c/ff99ed007f065198fd723152405c22aa558f700b git.kernel.org: https://git.kernel.org/stable/c/453d7198a0ab07a12d46e0575861ac7b932da17e