Improper Check for Unusual or Exceptional Conditions in Linux kernel - CVE-2026-89672

 

Improper Check for Unusual or Exceptional Conditions in Linux kernel - CVE-2026-89672

Published: September 12, 2026


Vulnerability identifier: #VU149138
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-89672
CWE-ID: CWE-754
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to remove POSIX ACLs.

The vulnerability exists due to improper handling of omitted ACL fields in the NFSACL v2 SETACL handler when processing SETACL requests with omitted ACL mask bits. A remote attacker can send a SETACL request with omitted ACL mask bits to remove POSIX ACLs.

A request containing only the NFS_ACL mask bit removes the directory's default ACL, while a request with a zero mask removes both ACL types.


Affected software

Linux kernel

How to mitigate CVE-2026-89672

Install security update from vendor's repository.


External References

Related Security Bulletins