7.1

CVE-2026-64298

NFSv4: include MAY_WRITE in open permission mask for O_TRUNC

In the Linux kernel, the following vulnerability has been resolved:

NFSv4: include MAY_WRITE in open permission mask for O_TRUNC

POSIX requires write permission to truncate a file, so an open() that
specifies O_TRUNC must be authorized for write access regardless of the
O_ACCMODE access mode.

nfs_open_permission_mask() builds the access mask passed to
nfs_may_open(), which is the local authorization gate for OPENs the
client serves itself from a cached write delegation via the
can_open_delegated() path in nfs4_try_open_cached().  The mask is
derived from O_ACCMODE alone, so an open(O_RDONLY | O_TRUNC) against a
file the caller cannot write requests only MAY_READ and passes the
local check.  The OPEN is then satisfied locally and the truncation is
issued to the server as a SETATTR(size=0) over the delegation stateid,
which the server accepts under standard write-delegation semantics.
POSIX requires that this open fail with EACCES.

Include MAY_WRITE in the mask whenever O_TRUNC is set so the local
check matches the access the server would have enforced.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinuxLinux Kernel Version >= 2.6.24 < 5.10.261
LinuxLinux Kernel Version >= 5.11 < 5.15.212
LinuxLinux Kernel Version >= 5.16 < 6.1.178
LinuxLinux Kernel Version >= 6.2 < 6.6.145
LinuxLinux Kernel Version >= 6.7 < 6.12.96
LinuxLinux Kernel Version >= 6.13 < 6.18.39
LinuxLinux Kernel Version >= 6.19 < 7.1.4
LinuxLinux Kernel Version7.2 Updaterc1
LinuxLinux Kernel Version7.2 Updaterc2
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.056
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/4817c8974315b666e895b7d1bb83cd3664c323b1
Patch
https://git.kernel.org/stable/c/cb148a2762d644bff1894728e8835a9a4b84f9ea
Patch
https://git.kernel.org/stable/c/30fdf4df6c3c00efec947e4ddf97f0fdd4473628
Patch
https://git.kernel.org/stable/c/22c1fd1355ad4ca27aa7f0fa02719122dd92d9de
Patch
https://git.kernel.org/stable/c/6bd7d0a06b53c4e797e1a9cea0d2d41aa1b26230
Patch
https://git.kernel.org/stable/c/a937e92c1d00534b5c2e3e9f4381b7e988180797
Patch
https://git.kernel.org/stable/c/e36501b7d4abdcd6d69a7cb901b2f286b7a3d041
Patch
https://git.kernel.org/stable/c/5140f099ecd8a2f2808b7f7b720ee1bad8468974
Patch