Improper Check for Unusual or Exceptional Conditions in Linux kernel - CVE-2026-89672
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to remove POSIX ACLs.
The vulnerability exists due to improper handling of omitted ACL fields in the NFSACL v2 SETACL handler when processing SETACL requests with omitted ACL mask bits. A remote attacker can send a SETACL request with omitted ACL mask bits to remove POSIX ACLs.
A request containing only the NFS_ACL mask bit removes the directory's default ACL, while a request with a zero mask removes both ACL types.