Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

DEBIAN-CVE-2026-89671

In the Linux kernel, the following vulnerability has been resolved: nfsd: gate nfs3 setacl by argp->mask nfsd3_proc_setacl() calls set_posix_acl() unconditionally for both ACL_TYPE_ACCESS and ACL_TY...
Back to all
CVE

DEBIAN-CVE-2026-89671

In the Linux kernel, the following vulnerability has been resolved: nfsd: gate nfs3 setacl by argp->mask nfsd3_proc_setacl() calls set_posix_acl() unconditionally for both ACL_TYPE_ACCESS and ACL_TY...

In the Linux kernel, the following vulnerability has been resolved:  nfsd: gate nfs3 setacl by argp->mask  nfsd3procsetacl() calls setposixacl() unconditionally for both ACLTYPEACCESS and ACLTYPEDEFAULT, passing argp->aclaccess and argp->acldefault verbatim. The NFSv3 ACL decoder only populates those pointers when the corresponding mask bit is set:      nfs3svcdecodesetaclargs()       if (args->mask & NFSACL)    decode into aclaccess       if (args->mask & NFSDFACL)  decode into acldefault       /* otherwise the pointer stays NULL (pcargzero) */      nfsd3procsetacl()       setposixacl(.., ACLTYPEACCESS,  argp->aclaccess)       setposixacl(.., ACLTYPEDEFAULT, argp->acldefault)  setposixacl(idmap, dentry, type, NULL) is the VFS "remove this ACL type" operation. A NULL pointer that means "the client did not send this arm" is therefore indistinguishable from "the client asked to remove this ACL". A SETACL with mask=NFSACL silently drops the directory's default ACL; mask=0 drops both.  The sibling nfsd3procgetacl() already consults argp->mask before touching each arm; mirror that in setacl.  Fix by wrapping each setposixacl() call in the matching mask bit check and initializing error to 0 before inodelock so that a request with neither bit set leaves the on-disk ACLs untouched and returns nfsok. The outdroplock path and the unconditional posixaclrelease() at out: are preserved; both NULL-tolerate the skipped arms.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
-
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
C
H
U
-

Related Resources

No items found.

References

https://security-tracker.debian.org/tracker/CVE-2026-89671

Severity

9.1

CVSS Score
0
10

Basic Information

Base CVSS
9.1
EPSS Probability
0%
EPSS Percentile
0%
Introduced Version
0
Fix Available
6.12.111-1,7.2.6-1,6.12.111-1~deb12u1

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading