Improper access control in Linux kernel - CVE-2026-90263
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to modify POSIX ACLs on a read-only Btrfs filesystem.
The vulnerability exists due to improper access control in the btrfs_set_acl POSIX ACL-setting path when setting a POSIX ACL on a Btrfs filesystem whose read-only property is enabled. A local user can set a POSIX ACL to modify POSIX ACLs on a read-only Btrfs filesystem.