Impact
The vulnerability in the Linux kernel NFS server occurs when a SETACL request contains the NFS_ACL mask bit server passes a NULL pointer for the missing field to set_posix_acl to delete that ACL type. This allows an attacker with permission to modify ACLs to remove default ACLs from a directory, effectively weakening the directory files. The flaw is identified as CWE-266 and has a CVSS score of 9.1,
Affected Systems
All Linux systems that include the vulnerable nfsd implementation and have not applied the upstream patch are affected. This includes any kernel version shipping the nfs2 setacl code before the bug fix, regardless of distribution.
Risk and Exploitability
The CVSS score of 9.1 reflects a high risk of exploitation. The EPSS score is less than 1%, indicating a low probability of exploitation at this time. The defect is not currently present in the CISA KEV catalog. The likely attack vector is a remote NFS client that has permission to issue SETACL operations. An attacker who can craft such a request may delete default ACLs and thus elevate privileges or gain unauthorized file access.
OpenCVE Enrichment
Debian DSA