SB20260912115 - Improper Check for Unusual or Exceptional Conditions in Linux kernel nfsd
Published: September 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper Check for Unusual or Exceptional Conditions (CVE-ID: CVE-2026-89672)
CWE-ID: CWE-754 - Improper Check for Unusual or Exceptional Conditions
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to remove POSIX ACLs.
The vulnerability exists due to improper handling of omitted ACL fields in the NFSACL v2 SETACL handler when processing SETACL requests with omitted ACL mask bits. A remote attacker can send a SETACL request with omitted ACL mask bits to remove POSIX ACLs.
A request containing only the NFS_ACL mask bit removes the directory's default ACL, while a request with a zero mask removes both ACL types.
Remediation
Install update from vendor's website.