Description
In the Linux kernel, the following vulnerability has been resolved:

nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create()

nfsd4_create() stores the return value of nfsd4_acl_to_attr() in
status, but the switch(create->cr_type) block unconditionally
overwrites it in every branch. ACL translation errors are silently
discarded, and the CREATE proceeds without the requested ACL.

Add an early exit check after nfsd4_acl_to_attr(), matching the
pattern already used in nfsd4_setattr().

[ cel: prefer NFS4ERR_BADTYPE over NFS4ERR_ATTRNOTSUPP ]
Published: 2026-09-11
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Inadequate ACL enforcement allowing unintended file permissions
Action: Patch
AI Analysis

Impact

The flaw resides in the NFSv4 server’s file creation routine, where an ACL supplied by a client is translated into Linux permission bits and stored in a status variable. The subsequent logic then overwrites this status unconditionally, discarding any error returned by the ACL translation. When a client provides a malformed or unsupported ACL, the failure is silently ignored and the file is created with the server’s default ACL instead of the requested permissions. This results in files being granted incorrect privileges, a classic example of error-checking ignored (CWE‑252).

Affected Systems

All Linux kernel releases that include the NFSv4 server component and that have not integrated the upstream patch identified by commit 2c7912732184773dbd371a411da87af1cc080b are affected. The patch restores proper error checking after ACL translation, ensuring that malformed ACLs do not result in default permissions.

Risk and Exploitability

The CVSS base score of 7.1 indicates a medium‑to‑high severity vulnerability. The EPSS score of <1 % shows that the likelihood of exploitation is very low. The vulnerability is not listed in the CISA KEV catalog. Based the attack vector requires network access to the NFS service and the ability to send a crafted CREATE request containing a bad ACL. An attacker would need the ability to write to the NFS share. No further escalation beyond incorrect file permissions is implied by the available information.

Generated by OpenCVE AI on September 15, 2026 at 20:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the upstream patch (commit 2c7912732184773dbd371a411da87af1cc080b includes this commit
  • Reload the NFS module or reboot the system so that the patched code takes effect
  • If a patch or upgrade cannot be applied immediately, disable ACL support on the NFS server or restrict client write privileges to reduce the risk of unintended file permissions

Generated by OpenCVE AI on September 15, 2026 at 20:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 21 Sep 2026 13:30:00 +0000


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-252
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create() nfsd4_create() stores the return value of nfsd4_acl_to_attr() in status, but the switch(create->cr_type) block unconditionally overwrites it in every branch. ACL translation errors are silently discarded, and the CREATE proceeds without the requested ACL. Add an early exit check after nfsd4_acl_to_attr(), matching the pattern already used in nfsd4_setattr(). [ cel: prefer NFS4ERR_BADTYPE over NFS4ERR_ATTRNOTSUPP ]
Title nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-21T13:14:48.601Z

Reserved: 2026-09-11T19:38:34.749Z

Link: CVE-2026-89693

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:56.380

Modified: 2026-09-21T14:17:25.340

Link: CVE-2026-89693

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:46:12Z

Links: CVE-2026-89693 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:45:20Z

Weaknesses