9.1
CVE-2026-89672
- EPSS 0.52%
- Veröffentlicht 11.09.2026 19:45:57
- Zuletzt bearbeitet 14.09.2026 13:19:19
- Erkennungen
nfsd: gate nfs2 setacl by argp->mask
In the Linux kernel, the following vulnerability has been resolved: nfsd: gate nfs2 setacl by argp->mask The NFSACL v2 SETACL path shares the decoder convention used by its v3 sibling: nfsaclsvc_decode_setaclargs() fills in argp->acl_access only when NFS_ACL is set in the request mask and argp->acl_default only when NFS_DFACL is set, leaving the other pointer NULL because the argument buffer is zeroed up to pc_argzero before decode. nfsacld_proc_setacl() then hands both pointers to set_posix_acl() unconditionally. set_posix_acl(idmap, dentry, type, NULL) is the VFS "remove this ACL type" operation, so an omitted arm is indistinguishable from an explicit request to delete that ACL. A SETACL carrying only NFS_ACL silently strips the directory's default ACL; mask=0 strips both. This is the same defect just fixed in nfsd3_proc_setacl(); apply the same remedy. Gate each set_posix_acl() call on its mask bit and initialize error to 0 so that a request with neither bit set leaves the on-disk ACLs untouched and returns success. The out_drop_lock path and the unconditional posix_acl_release() in nfsaclsvc_release_setacl() already tolerate the skipped arms.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
a257cdd0e2179630d3201c32ba14d7fcb3c3a055
Version <
8e4422b05f410f95c51b68a0db4bf1d87f6d22f5
Status
affected
Version
a257cdd0e2179630d3201c32ba14d7fcb3c3a055
Version <
e41d173d9dc735cecb15ab7aa63ecab09338f81b
Status
affected
Version
a257cdd0e2179630d3201c32ba14d7fcb3c3a055
Version <
f951b22dbeec46f2e0fba81cb80d1b0c686b61eb
Status
affected
Version
a257cdd0e2179630d3201c32ba14d7fcb3c3a055
Version <
37eea38e7898538f0ec5f1eb8b18d8646e4be41c
Status
affected
Version
a257cdd0e2179630d3201c32ba14d7fcb3c3a055
Version <
a3a7e20ed66d3f04d37883c398da8a113b430769
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
2.6.13
Status
affected
Version
0
Version <
2.6.13
Status
unaffected
Version <=
6.6.*
Version
6.6.157
Status
unaffected
Version <=
6.12.*
Version
6.12.109
Status
unaffected
Version <=
6.18.*
Version
6.18.50
Status
unaffected
Version <=
7.2.*
Version
7.2.4
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.52% | 0.428 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
https://git.kernel.org/stable/c/e41d173d9dc735cecb15ab7aa63ecab09338f81b
https://git.kernel.org/stable/c/f951b22dbeec46f2e0fba81cb80d1b0c686b61eb
https://git.kernel.org/stable/c/37eea38e7898538f0ec5f1eb8b18d8646e4be41c
https://git.kernel.org/stable/c/a3a7e20ed66d3f04d37883c398da8a113b430769
https://git.kernel.org/stable/c/8e4422b05f410f95c51b68a0db4bf1d87f6d22f5