9.1

CVE-2026-89672

nfsd: gate nfs2 setacl by argp->mask

In the Linux kernel, the following vulnerability has been resolved:

nfsd: gate nfs2 setacl by argp->mask

The NFSACL v2 SETACL path shares the decoder convention used by its
v3 sibling: nfsaclsvc_decode_setaclargs() fills in argp->acl_access
only when NFS_ACL is set in the request mask and argp->acl_default
only when NFS_DFACL is set, leaving the other pointer NULL because
the argument buffer is zeroed up to pc_argzero before decode.

nfsacld_proc_setacl() then hands both pointers to set_posix_acl()
unconditionally. set_posix_acl(idmap, dentry, type, NULL) is the VFS
"remove this ACL type" operation, so an omitted arm is
indistinguishable from an explicit request to delete that ACL. A
SETACL carrying only NFS_ACL silently strips the directory's default
ACL; mask=0 strips both.

This is the same defect just fixed in nfsd3_proc_setacl(); apply the
same remedy. Gate each set_posix_acl() call on its mask bit and
initialize error to 0 so that a request with neither bit set leaves
the on-disk ACLs untouched and returns success. The out_drop_lock
path and the unconditional posix_acl_release() in
nfsaclsvc_release_setacl() already tolerate the skipped arms.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version a257cdd0e2179630d3201c32ba14d7fcb3c3a055
Version < 8e4422b05f410f95c51b68a0db4bf1d87f6d22f5
Status affected
Version a257cdd0e2179630d3201c32ba14d7fcb3c3a055
Version < e41d173d9dc735cecb15ab7aa63ecab09338f81b
Status affected
Version a257cdd0e2179630d3201c32ba14d7fcb3c3a055
Version < f951b22dbeec46f2e0fba81cb80d1b0c686b61eb
Status affected
Version a257cdd0e2179630d3201c32ba14d7fcb3c3a055
Version < 37eea38e7898538f0ec5f1eb8b18d8646e4be41c
Status affected
Version a257cdd0e2179630d3201c32ba14d7fcb3c3a055
Version < a3a7e20ed66d3f04d37883c398da8a113b430769
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.13
Status affected
Version 0
Version < 2.6.13
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.52% 0.428
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/e41d173d9dc735cecb15ab7aa63ecab09338f81b
https://git.kernel.org/stable/c/f951b22dbeec46f2e0fba81cb80d1b0c686b61eb
https://git.kernel.org/stable/c/37eea38e7898538f0ec5f1eb8b18d8646e4be41c
https://git.kernel.org/stable/c/a3a7e20ed66d3f04d37883c398da8a113b430769
https://git.kernel.org/stable/c/8e4422b05f410f95c51b68a0db4bf1d87f6d22f5