CVE-2026-89672
Received Received - Intake

Linux kernel NFSACL v2 SETACL Privilege Escalation

Vulnerability report for CVE-2026-89672, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: nfsd: gate nfs2 setacl by argp->mask The NFSACL v2 SETACL path shares the decoder convention used by its v3 sibling: nfsaclsvc_decode_setaclargs() fills in argp->acl_access only when NFS_ACL is set in the request mask and argp->acl_default only when NFS_DFACL is set, leaving the other pointer NULL because the argument buffer is zeroed up to pc_argzero before decode. nfsacld_proc_setacl() then hands both pointers to set_posix_acl() unconditionally. set_posix_acl(idmap, dentry, type, NULL) is the VFS "remove this ACL type" operation, so an omitted arm is indistinguishable from an explicit request to delete that ACL. A SETACL carrying only NFS_ACL silently strips the directory's default ACL; mask=0 strips both. This is the same defect just fixed in nfsd3_proc_setacl(); apply the same remedy. Gate each set_posix_acl() call on its mask bit and initialize error to 0 so that a request with neither bit set leaves the on-disk ACLs untouched and returns success. The out_drop_lock path and the unconditional posix_acl_release() in nfsaclsvc_release_setacl() already tolerate the skipped arms.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves improper handling of NFSv2 SETACL requests. The issue occurs because the kernel fails to properly check the request mask when setting ACLs, leading to unintended removal of ACLs. Specifically, if the mask is not set correctly, the kernel may strip directory ACLs or default ACLs unintentionally.

Detection Guidance

This vulnerability affects the Linux kernel's NFSv2 SETACL functionality. Detection requires checking kernel versions and NFS server configurations. Inspect running kernel version with 'uname -r' and check NFS server logs for ACL-related errors. Monitor for unexpected ACL modifications or deletions on NFS shares.

Impact Analysis

This vulnerability could allow an attacker with access to an NFS share to modify or remove access control lists (ACLs) on files or directories without proper authorization. This might result in unauthorized access to sensitive data or disruption of normal file permissions.

Compliance Impact

This vulnerability could lead to unauthorized access or modification of sensitive data, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Organizations using affected Linux kernel versions with NFSv2 may face compliance risks due to potential data exposure or integrity issues.

Mitigation Strategies

Update the Linux kernel to the latest patched version to resolve this NFS ACL vulnerability. Monitor NFS server logs for unusual ACL modification attempts or errors related to setacl operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89672. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart