Description
In the Linux kernel, the following vulnerability has been resolved:

nfsd: cap decoded POSIX ACL count to bound sort cost

nfsd4_decode_posixacl() reads a u32 entry count off the wire and passes
it straight to posix_acl_alloc() and sort_pacl_range(). The latter is
an O(n^2) bubble sort, so a client-chosen count drives unbounded CPU in
the server's compound processing path.

nfsd4_decode_posixacl()
xdr_stream_decode_u32(&count) /* uncapped u32 */
posix_acl_alloc(count, GFP_KERNEL)
sort_pacl_range(*acl, 0, count - 1) /* O(n^2) bubble sort */

The encoder side in the same file already rejects ACLs whose a_count
exceeds NFS_ACL_MAX_ENTRIES, but the decoder introduced in commit
5fc51dfc2eb1 ("NFSD: Add support for XDR decoding POSIX draft ACLs")
omitted the symmetric check.

Fix by rejecting a wire count greater than NFS_ACL_MAX_ENTRIES with
nfserr_inval, before any allocation, so the sort is bounded by
NFS_ACL_MAX_ENTRIES^2 comparisons.

While we're in here, also fix the nfserr_resource return if
posix_acl_alloc() fails. That's not a legal error code for v4.1+. Change
it to return nfserr_jukebox as that's more appropriate for memory
allocation failures.
Published: 2026-09-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Unbounded CPU Consumption
Action: Upgrade Kernel
AI Analysis

Impact

The Linux NFS server contains a flaw in the nfsd4_decode_posixacl routine, where a 32‑bit ACL entry count is read from the network and passed directly to the allocation and bubble‑sort functions. Because the count is not limited, a malicious client can supply an arbitrarily large number, forcing the kernel to perform an unbounded O(n²) sort that consumes excessive CPU resources. This vulnerability trigger a denial of service without authentication.

Affected Systems

Affected systems are Linux kernels that expose an NFS server and lack the bounds‑check introduced by commit 5fc51dfc2eb1. Any distribution shipping a kernel revision prior to integrating this commit is potentially vulnerable; kernels that have received the patch are considered safe.

Risk and Exploitability

The CVSS score of 7.5. The EPSS score is below 1%, indicating a low but non‑zero likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. An attacker4 requests to the target server; by crafting a request with a very large ACL count the server will waste CPU cycles performing the bubble sort before rejecting the request with nfserr_inval. No additional privileges or authentication are required.

Generated by OpenCVE AI on September 15, 2026 at 20:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that contains the 5fc51dfc2eb1 bounds‑check commit or later.
  • Recompile the kernel without CONFIG_POSIX_ACL support to disable POSIX ACL handling on the NFS server.
  • As a temporary measure, configure the network to block or rate‑limit NFSv4 requests that carry unusually large ACL counts.

Generated by OpenCVE AI on September 15, 2026 at 20:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Sat, 12 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-606
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Sat, 12 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nfsd: cap decoded POSIX ACL count to bound sort cost nfsd4_decode_posixacl() reads a u32 entry count off the wire and passes it straight to posix_acl_alloc() and sort_pacl_range(). The latter is an O(n^2) bubble sort, so a client-chosen count drives unbounded CPU in the server's compound processing path. nfsd4_decode_posixacl() xdr_stream_decode_u32(&count) /* uncapped u32 */ posix_acl_alloc(count, GFP_KERNEL) sort_pacl_range(*acl, 0, count - 1) /* O(n^2) bubble sort */ The encoder side in the same file already rejects ACLs whose a_count exceeds NFS_ACL_MAX_ENTRIES, but the decoder introduced in commit 5fc51dfc2eb1 ("NFSD: Add support for XDR decoding POSIX draft ACLs") omitted the symmetric check. Fix by rejecting a wire count greater than NFS_ACL_MAX_ENTRIES with nfserr_inval, before any allocation, so the sort is bounded by NFS_ACL_MAX_ENTRIES^2 comparisons. While we're in here, also fix the nfserr_resource return if posix_acl_alloc() fails. That's not a legal error code for v4.1+. Change it to return nfserr_jukebox as that's more appropriate for memory allocation failures.
Title nfsd: cap decoded POSIX ACL count to bound sort cost
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:33:18.615Z

Reserved: 2026-09-11T19:38:34.750Z

Link: CVE-2026-89695

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:56.610

Modified: 2026-09-13T07:17:35.230

Link: CVE-2026-89695

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:46:14Z

Links: CVE-2026-89695 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:45:20Z

Weaknesses
  • CWE-606

    Unchecked Input for Loop Condition