Improper Check for Unusual or Exceptional Conditions in Linux kernel - CVE-2026-89693
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to create objects without the requested access control lists.
The vulnerability exists due to improper handling of ACL translation errors in nfsd4_create() when processing NFSv4 CREATE requests containing ACLs. A remote attacker can submit a crafted NFSv4 CREATE request that causes ACL translation to fail to create objects without the requested access control lists.