nfsd: gate nfs2 setacl by argp->mask
Summary
| CVE | CVE-2026-89672 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-11 20:19:53 UTC |
| Updated | 2026-09-11 20:19:53 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
nfsd: gate nfs2 setacl by argp->mask
The NFSACL v2 SETACL path shares the decoder convention used by its
v3 sibling: nfsaclsvc_decode_setaclargs() fills in argp->acl_access
only when NFS_ACL is set in the request mask and argp->acl_default
only when NFS_DFACL is set, leaving the other pointer NULL because
the argument buffer is zeroed up to pc_argzero before decode.
nfsacld_proc_setacl() then hands both pointers to set_posix_acl()
unconditionally. set_posix_acl(idmap, dentry, type, NULL) is the VFS
"remove this ACL type" operation, so an omitted arm is
indistinguishable from an explicit request to delete that ACL. A
SETACL carrying only NFS_ACL silently strips the directory's default
ACL; mask=0 strips both.
This is the same defect just fixed in nfsd3_proc_setacl(); apply the
same remedy. Gate each set_posix_acl() call on its mask bit and
initialize error to 0 so that a request with neither bit set leaves
the on-disk ACLs untouched and returns success. The out_drop_lock
path and the unconditional posix_acl_release() in
nfsaclsvc_release_setacl() already tolerate the skipped arms. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected a257cdd0e2179630d3201c32ba14d7fcb3c3a055 e41d173d9dc735cecb15ab7aa63ecab09338f81b git |
Not specified |
| CNA |
Linux |
Linux |
affected a257cdd0e2179630d3201c32ba14d7fcb3c3a055 f951b22dbeec46f2e0fba81cb80d1b0c686b61eb git |
Not specified |
| CNA |
Linux |
Linux |
affected a257cdd0e2179630d3201c32ba14d7fcb3c3a055 37eea38e7898538f0ec5f1eb8b18d8646e4be41c git |
Not specified |
| CNA |
Linux |
Linux |
affected a257cdd0e2179630d3201c32ba14d7fcb3c3a055 a3a7e20ed66d3f04d37883c398da8a113b430769 git |
Not specified |
| CNA |
Linux |
Linux |
affected 2.6.13 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 2.6.13 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.109 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.50 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.4 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/e41d173d9dc735cecb15ab7aa63ecab09338f81b |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/f951b22dbeec46f2e0fba81cb80d1b0c686b61eb |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/a3a7e20ed66d3f04d37883c398da8a113b430769 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/37eea38e7898538f0ec5f1eb8b18d8646e4be41c |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.