CVE-2026-89672
In the Linux kernel, the following vulnerability has been resolved:
nfsd: gate nfs2 setacl by argp->mask
The NFSACL v2 SETACL path shares the decoder convention used by its
v3 sibling: nfsaclsvcdecodesetaclargs() fills in argp->acl_access
only when NFSACL is set in the request mask and argp->acldefault
only when NFS_DFACL is set, leaving the other pointer NULL because
the argument buffer is zeroed up to pc_argzero before decode.
nfsacldprocsetacl() then hands both pointers to setposixacl()
unconditionally. setposixacl(idmap, dentry, type, NULL) is the VFS
"remove this ACL type" operation, so an omitted arm is
indistinguishable from an explicit request to delete that ACL. A
SETACL carrying only NFS_ACL silently strips the directory's default
ACL; mask=0 strips both.
This is the same defect just fixed in nfsd3procsetacl(); apply the
same remedy. Gate each setposixacl() call on its mask bit and
initialize error to 0 so that a request with neither bit set leaves
the on-disk ACLs untouched and returns success. The outdroplock
path and the unconditional posixaclrelease() in
nfsaclsvcreleasesetacl() already tolerate the skipped arms.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/37eea38e7898538f0ec5f1eb8b18d8646e4be41c, https://git.kernel.org/stable/c/8e4422b05f410f95c51b68a0db4bf1d87f6d22f5, https://git.kernel.org/stable/c/a3a7e20ed66d3f04d37883c398da8a113b430769, https://git.kernel.org/stable/c/e41d173d9dc735cecb15ab7aa63ecab09338f81b, https://git.kernel.org/stable/c/f951b22dbeec46f2e0fba81cb80d1b0c686b61eb, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89672.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89672, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git