In the Linux kernel, the following vulnerability has been resolved:
nfsd: fix posixacl leak and ignored error in nfsd4create_file
nfsd4createfile() has two bugs in its ACL handling:
The return value of nfsd4acltoattr() is silently discarded. When the NFSv4-to-POSIX ACL conversion fails (e.g., -EINVAL for unsupported ACE types), the file is created without any ACL and the client receives NFS4OK. This violates RFC 7530/8881 which require the server to reject unsupported attributes on CREATE.
When startcreating() fails after ACL attributes have been populated in attrs (either via nfsd4acltoattr or via ownership transfer from open->opdpacl/oppacl), the function jumps to outwrite which skips nfsdattrsfree(). The posixacl allocations are leaked. A client can trigger this repeatedly with OPEN(CREATE), ACL attributes, and an invalid filename (e.g., longer than NAME_MAX).
Fix both by capturing the nfsd4acltoattr() return value and by changing the early error paths to jump to out instead of outwrite. Initialize child to ERRPTR(-EINVAL) so that endcreating() is safe to call even if start_creating() was never reached.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53396.json",
"cna_assigner": "Linux"
}