Impact
The flaw resides in the NFSv4 server’s file creation routine, where an ACL supplied by a client is translated into Linux permission bits and stored in a status variable. The subsequent logic then overwrites this status unconditionally, discarding any error returned by the ACL translation. When a client provides a malformed or unsupported ACL, the failure is silently ignored and the file is created with the server’s default ACL instead of the requested permissions. This results in files being granted incorrect privileges, a classic example of error-checking ignored (CWE‑252).
Affected Systems
All Linux kernel releases that include the NFSv4 server component and that have not integrated the upstream patch identified by commit 2c7912732184773dbd371a411da87af1cc080b are affected. The patch restores proper error checking after ACL translation, ensuring that malformed ACLs do not result in default permissions.
Risk and Exploitability
The CVSS base score of 7.1 indicates a medium‑to‑high severity vulnerability. The EPSS score of <1 % shows that the likelihood of exploitation is very low. The vulnerability is not listed in the CISA KEV catalog. Based the attack vector requires network access to the NFS service and the ability to send a crafted CREATE request containing a bad ACL. An attacker would need the ability to write to the NFS share. No further escalation beyond incorrect file permissions is implied by the available information.
OpenCVE Enrichment
Debian DSA