CVE-2026-89671
Received Received - Intake

Privilege Escalation in Linux Kernel NFS Server

Vulnerability report for CVE-2026-89671, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: nfsd: gate nfs3 setacl by argp->mask nfsd3_proc_setacl() calls set_posix_acl() unconditionally for both ACL_TYPE_ACCESS and ACL_TYPE_DEFAULT, passing argp->acl_access and argp->acl_default verbatim. The NFSv3 ACL decoder only populates those pointers when the corresponding mask bit is set: nfs3svc_decode_setaclargs() if (args->mask & NFS_ACL) decode into acl_access if (args->mask & NFS_DFACL) decode into acl_default /* otherwise the pointer stays NULL (pc_argzero) */ nfsd3_proc_setacl() set_posix_acl(.., ACL_TYPE_ACCESS, argp->acl_access) set_posix_acl(.., ACL_TYPE_DEFAULT, argp->acl_default) set_posix_acl(idmap, dentry, type, NULL) is the VFS "remove this ACL type" operation. A NULL pointer that means "the client did not send this arm" is therefore indistinguishable from "the client asked to remove this ACL". A SETACL with mask=NFS_ACL silently drops the directory's default ACL; mask=0 drops both. The sibling nfsd3_proc_getacl() already consults argp->mask before touching each arm; mirror that in setacl. Fix by wrapping each set_posix_acl() call in the matching mask bit check and initializing error to 0 before inode_lock so that a request with neither bit set leaves the on-disk ACLs untouched and returns nfs_ok. The out_drop_lock path and the unconditional posix_acl_release() at out: are preserved; both NULL-tolerate the skipped arms.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves improper handling of NFSv3 ACL (Access Control List) operations. When a client sends a SETACL request without specifying certain ACL types in the mask, the kernel incorrectly interprets this as a request to remove those ACLs. This happens because the kernel unconditionally calls set_posix_acl() for both ACL_TYPE_ACCESS and ACL_TYPE_DEFAULT, even when the client did not send those ACLs.

Detection Guidance

This vulnerability affects the Linux kernel's NFSv3 ACL handling. Detection requires checking kernel versions and NFS server configurations. Inspect running kernel version with 'uname -a' and verify if NFSv3 services are enabled. Check NFS exports with 'cat /proc/fs/nfs/exports'. Monitor system logs for unusual ACL modification attempts.

Impact Analysis

This vulnerability could allow an attacker to unintentionally remove ACLs from files or directories by sending a malformed SETACL request. This might lead to unauthorized access to sensitive data if ACLs are removed, as the default permissions could be less restrictive than intended.

Compliance Impact

This vulnerability in the Linux kernel's NFSv3 ACL handling could lead to unintended removal of ACLs, potentially causing unauthorized access to sensitive data. This may violate compliance requirements under GDPR (data protection) and HIPAA (health data privacy) by exposing protected information.

Mitigation Strategies

Immediate mitigation requires updating the Linux kernel to a patched version. Disable NFSv3 services if not required. Apply kernel patches from your distribution vendor. Restrict NFS exports to trusted networks only. Monitor for unauthorized ACL changes in system logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89671. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart