Impact
In the Linux kernel, the NFSv3 setacl operation unconditionally calls the VFS set_posix_acl function for both ACL_TYPE_ACCESS and ACL_TYPE_DEFAULT, passing pointers that may be NULL when the client does not supply the corresponding mask bits. The NFSv3 decoder leaves these pointers NULL, which the VFS interprets as a request to delete that ACL type. Consequently, a SETACL with only the NFS_ACL bit silently removes the directory’s default ACL, and a mask of 0 drops both ACL types. This defect allows an attacker to erode access controls on directories exposed via NFSv3, potentially granting higher privilege access or disrupting normal file access patterns. This vulnerability is classified as CWE-115.
Affected Systems
All Linux kernel releases that contain the NFSv3 implementation before the upstream patch commits (e.g., 68a80b26, b3bff820, ff99ed00) are affected. The affected product is the Linux kernel; the specific version information is not listed, so all kernels lacking these commits are at risk.
Risk and Exploitability
The flaw carries a CVSS score of 9.1, indicating high severity, but its EPSS score is below 1%, suggesting that public exploitation is unlikely at present. It is not listed in the CISA KEV catalog. The adversary with network access to an NFSv3 server could send crafted SETACL requests that omit or misuse mask bits to remove ACLs, thereby weakening or bypassing intended permissions or disrupting service availability.
OpenCVE Enrichment
Debian DSA