CVE-2026-89671

Source
https://cve.org/CVERecord?id=CVE-2026-89671
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89671.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89671
Downstream
Published
2026-09-11T19:45:56Z
Modified
2026-09-13T03:47:20Z
Summary
nfsd: gate nfs3 setacl by argp->mask
Details

In the Linux kernel, the following vulnerability has been resolved:

nfsd: gate nfs3 setacl by argp->mask

nfsd3_proc_setacl() calls set_posix_acl() unconditionally for both ACL_TYPE_ACCESS and ACL_TYPE_DEFAULT, passing argp->acl_access and argp->acl_default verbatim. The NFSv3 ACL decoder only populates those pointers when the corresponding mask bit is set:

nfs3svc_decode_setaclargs()
  if (args->mask & NFS_ACL)    decode into acl_access
  if (args->mask & NFS_DFACL)  decode into acl_default
  /* otherwise the pointer stays NULL (pc_argzero) */

nfsd3_proc_setacl()
  set_posix_acl(.., ACL_TYPE_ACCESS,  argp->acl_access)
  set_posix_acl(.., ACL_TYPE_DEFAULT, argp->acl_default)

set_posix_acl(idmap, dentry, type, NULL) is the VFS "remove this ACL type" operation. A NULL pointer that means "the client did not send this arm" is therefore indistinguishable from "the client asked to remove this ACL". A SETACL with mask=NFS_ACL silently drops the directory's default ACL; mask=0 drops both.

The sibling nfsd3_proc_getacl() already consults argp->mask before touching each arm; mirror that in setacl.

Fix by wrapping each set_posix_acl() call in the matching mask bit check and initializing error to 0 before inode_lock so that a request with neither bit set leaves the on-disk ACLs untouched and returns nfs_ok. The out_drop_lock path and the unconditional posix_acl_release() at out: are preserved; both NULL-tolerate the skipped arms.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89671.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
a257cdd0e2179630d3201c32ba14d7fcb3c3a055
Fixed
68a80b26efdff1d09f8ae1773c6a915abb9e191d
Fixed
b3bff820d068ea59767d4e91a3258231a879da5f
Fixed
ff99ed007f065198fd723152405c22aa558f700b
Fixed
453d7198a0ab07a12d46e0575861ac7b932da17e

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89671.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.13
Fixed
6.12.109
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.50
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89671.json"